Sunday, 7 December 2025
31.2 C
Singapore
31.4 C
Thailand
26.6 C
Indonesia
25.4 C
Philippines

CrowdStrike report reveals surge in AI-driven ransomware and Chinese underground cybercrime markets

CrowdStrike’s 2025 APJ report reveals the rise of AI-powered ransomware and thriving Chinese underground cybercrime markets.

CrowdStrike has released its 2025 APJ eCrime Landscape Report, revealing a thriving Chinese-language cybercrime ecosystem and a surge in AI-powered ransomware operations across Asia Pacific and Japan (APJ). Despite strict internet controls and law enforcement efforts in China, anonymised underground marketplaces remain central to the region’s cybercrime economy, enabling actors to trade stolen data, malware, and illicit services while evading oversight.

These marketplaces, operating across clearnet, darknet, and encrypted messaging platforms, have processed billions of dollars in criminal transactions. Among them is Huione Guarantee, which handled an estimated US$27 billion in illicit trades before being disrupted earlier this year. Other platforms, including Chang’an and FreeCity, continue to offer a safe haven for Chinese-speaking actors focused on maintaining operational security.

The report, based on intelligence from CrowdStrike’s team of threat hunters and analysts monitoring more than 265 adversary groups, paints a picture of an increasingly sophisticated and industrialised cybercrime ecosystem that shows no signs of slowing down.

AI accelerates the next wave of ransomware threats

Artificial intelligence is rapidly reshaping the ransomware landscape, enabling adversaries to accelerate every stage of the attack chain. From more convincing social engineering campaigns to automated malware development, AI is fuelling a new generation of attacks targeting high-value organisations across the region.

The report highlights a surge in so-called “Big Game Hunting” ransomware campaigns, particularly in India, Australia, and Japan. Ransomware-as-a-Service (RaaS) providers such as KillSec and Funklocker, which use AI to develop and deploy their malware, were responsible for over 120 incidents. Manufacturing, technology, and financial services companies were among the most frequently targeted, with 763 victims publicly named on dedicated leak sites.

“eCrime actors are industrialising cybercrime across APJ through thriving underground markets and complex ransomware operations. Simultaneously, AI-developed malware enables adversaries to launch high-velocity, high-volume attacks,” said Adam Meyers, head of counter adversary operations at CrowdStrike. “Defenders must meet this new pace of attack with decisive action, powered by AI, informed by human experience, and unified in response.”

Financial manipulation and expanding cybercrime services

The report also details how Chinese-speaking threat actors have exploited Japanese trading accounts in coordinated account takeover campaigns. These operations compromised users to manipulate the value of thinly traded China-based stocks through pump-and-dump schemes. Using shared phishing infrastructure, the attackers stole victim data and sold it on underground platforms such as Chang’an Marketplace.

The industrialisation of eCrime is further driven by specialised service providers offering tools and infrastructure to support large-scale operations. Providers such as CDNCLOUD supply bulletproof hosting services, while Magical Cat delivers phishing-as-a-service platforms. Graves International SMS offers global spam distribution, all contributing to the rapid scaling of phishing, malware delivery, and monetisation schemes.

Meanwhile, remote access tools (RATs) including ChangemeRAT, ElseRAT, and WhiteFoxRAT have been deployed against Chinese- and Japanese-speaking users. These tools are distributed through tactics such as SEO poisoning, malvertising, and phishing campaigns disguised as purchase orders, allowing attackers to gain persistent access to compromised systems.

A growing challenge for defenders

The findings of the 2025 APJ eCrime Landscape Report highlight the growing challenge for organisations and governments across the region. The combination of resilient underground marketplaces, the industrialisation of cybercrime services, and the rise of AI-enhanced ransomware is rapidly increasing the speed, scale, and impact of attacks.

As cybercriminal operations evolve, defenders are under pressure to respond with equally advanced strategies. The report underscores the need for AI-powered defences, collaboration across industries, and proactive threat intelligence to counter increasingly sophisticated adversaries.

Hot this week

Nvidia partners with Mistral AI to accelerate new open model family

Nvidia and Mistral AI launch the Mistral 3 model family to boost enterprise AI performance across cloud and edge platforms.

Singapore FinTech Festival marks its 10th edition with focus on future finance technologies

Singapore FinTech Festival marks its 10th edition with record participation and a focus on technologies shaping future finance.

Kyndryl and Microsoft report rising sustainability commitment among Singapore businesses

Most Singapore businesses are expanding sustainability efforts but face challenges with data quality and limited AI adoption.

Solera highlights AI, sustainability and leadership at Insurtech Insights Asia

Solera showcases AI innovation, sustainability initiatives and leadership programmes at Insurtech Insights Asia in Hong Kong.

Audio-Technica unveils flagship ATH-ADX7000 open-air headphones

Audio-Technica releases the ATH-ADX7000, a flagship open-air headphone built around a new high-precision driver and lightweight design.

Google highlights Singapore’s top trending searches in 2025

Google reveals Singapore’s top trending searches for 2025, highlighting SG60 celebrations, elections, pop culture and financial concerns.

HPE expands hybrid cloud portfolio with new virtualisation, security and AI capabilities

HPE expands its GreenLake cloud portfolio with new virtualisation, security and AI capabilities to support modern hybrid cloud demands.

EOY music, comics and arts festival returns with new venue and expanded programme

EOY 2025 returns with a new venue, international guests and expanded activities celebrating Japanese pop culture in Singapore.

Tiger Brokers: Bringing institutional-grade AI intelligence to global retail investors

AI is redefining retail investing as platforms like Tiger Brokers’ TigerAI integrate verified intelligence, personalisation, and long-term wealth management to empower global investors.

Related Articles

Popular Categories