September 11, 2025  —  Acronis Threat Research Unit

Acronis Cyberthreats Update, September 2025

Authors:

Alexander Ivanyuk Senior Director, Technology

Irina Artioli Cyber Protection Evangelist, TRU Researcher

 

The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis Threat Research Unit (TRU) and Acronis sensors. Figures presented here were gathered in August 2025 and reflect threats that Acronis detected, as well as news stories from the public domain. This report represents a global outlook and is based on more than one million unique endpoints distributed around the world.

Acronis

Incidents of the month

Malware developers have misused Anthropic’s Claude Code — an AI-powered coding assistant — to create advanced ransomware as a service (RaaS) kits. A U.K.-based actor tracked as GTG-5004 relied almost entirely on Claude Code to author a sophisticated ransomware platform. The AI-generated modular ransomware components feature ChaCha20 stream cipher and RSA-based key management and functionality to target specific files, encrypt network shares and delete Windows shadow copies.

For evasion, the Claude-generated malware used refined techniques such as reflective DLL injection, syscall invocation, API hooking bypass, string obfuscation and anti-debugging — indicating advanced obfuscation abilities ushered in by AI support.

August malware detections

In August, Acronis Cyber Protect blocked over 520,000 malware threats on endpoints — an increase of 9.2 % from July.

The below tables show the percentage of Acronis clients that had at least one malware threat blocked at the endpoint, as well as the normalized percentage of clients with at least one malware detection. The higher the percentage, the higher the risk of a workload in that country being attacked by malware.

Acronis
Acronis

Protection

The aforementioned threats can be detected and mitigated with solutions from Acronis.

Acronis Cyber Protect Cloud protects against both known and never-before-seen threats through a multilayered protection approach. This includes behavior-based detection, AI- and ML-trained detections and anti-ransomware heuristics, which can detect and block encryption attempts and roll back any tampered files automatically without any user interaction.

Additional email security and URL filtering can help you protect against social engineering threats. And, your Acronis #CyberFit score helps you quickly identify systems that need attention, while integrated patch management makes updating your software to the latest versions simple.

Acronis XDR for Acronis Cyber Protect Cloud brings the visibility needed to understand attacks while simplifying the context for administrators and enabling efficient remediation of any threats.