Acronis Cyberthreats Update, January 2025

Authors:

Alexander Ivanyuk Senior Director, Technology

Irina Artioli Cyber Protection Evangelist

The Acronis Cyberthreats Update covers current cyberthreat activity and trends, as observed by Acronis Threat Research Unit (TRU) and sensors. Figures presented here were gathered in December of this year and reflect threats that we detected as well as news stories from the public domain. This report represents a global outlook and is based on more than one million unique endpoints distributed around the world.

Acronis

Incidents of the month

The Cl0p ransomware group has recently intensified its cybercriminal activities by exploiting a zero-day vulnerability in Cleo's file transfer products: LexiCom, VLTrader and Harmony. This strategic exploitation has led to unauthorized data access and theft from numerous organizations across various industries.

The specific vulnerability exploited by Cl0p is identified as CVE-2024-55956. This flaw allows unauthorized file write access, enabling attackers to infiltrate systems and exfiltrate sensitive data. This vulnerability differs from previous issues in Cleo's products, indicating a distinct exploitation strategy employed by Cl0p. Their previous attacks include breaches involving Accellion FTA, GoAnywhere MFT, and MOVEit Transfer platforms, resulting in significant data compromises for numerous organizations.

In December 2024, Cl0p began extorting 68 companies affected by these breaches. The group issued ultimatums via their dark web portal, granting victims 48 hours to initiate ransom negotiations.

December malware detections

In December, Acronis Cyber Protect blocked 2.3 million malware threats on endpoints — a 32% increase from November.

The below tables show the percentage of Acronis clients that had at least one malware threat blocked at the endpoint (this number has been hovering around 12% for the last year), as well as the normalized percentage of clients with at least one malware detection. The higher the percentage, the higher the risk of a workload in that country being attacked by malware.

Acronis
Acronis
Acronis

Protection

The aforementioned threats can be detected and mitigated with solutions from Acronis.

Acronis Cyber Protect Cloud protects against both known and never-before-seen threats through a multilayered protection approach. This includes behavior-based detection, AI- and ML-trained detections and anti-ransomware heuristics, which can detect and block encryption attempts and roll back any tampered files automatically without any user interaction.

Additional advanced email security and URL filtering can help you protect against social engineering threats. And your Acronis #CyberFit score helps you quickly identify systems that need attention, while the integrated patch management makes updating your software to the latest versions simple.

Advanced Security + Extended Detection and Response (XDR) for Acronis Cyber Protect Cloud brings the visibility needed to understand attacks while simplifying the context for administrators and enabling efficient remediation of any threats.