Uncovering Ransomware Risk: A Machine Learning Approach to Predicting Attacks

Friday 21 March 2025


Ransomware attacks have been a growing concern for businesses and individuals alike, with devastating consequences for those who fall victim to these malicious cyberattacks. A recent study has shed light on a new approach to assessing and prioritizing ransomware risk, offering hope for more effective protection against these attacks.


The researchers developed a machine learning model that leverages large language models (LLMs) to identify patterns in ransomware group behavior and predict the likelihood of an entity being targeted. The team used a dataset consisting of 8,200 records, evenly split between safe and unsafe entities, all derived from authentic ransomware victims.


The LLMs were trained on a vast amount of text data, including ransomware bulletins, threat reports, and news items, to learn the tactics, techniques, and procedures (TTPs) employed by different groups. This enabled the model to generate profiles of the entities targeted by these groups, as well as their corresponding risk scores.


One of the key findings was that the company profile plays a significant role in determining the likelihood of being targeted. For instance, companies with larger employee numbers and higher revenue are more likely to be targeted by ransomware groups. Additionally, companies located in the United States were found to be disproportionately represented in the dataset, highlighting a potential geographical bias.


The researchers also discovered that the Enumerated Weighted Moving Average (EWMA) of the ransomware group’s activity level is a crucial factor in predicting risk. Groups with higher EWMA scores are more likely to target entities, indicating an increased threat.


The study’s findings have important implications for organizations seeking to mitigate their ransomware risk. By incorporating these factors into their risk assessments, companies can prioritize their defenses and allocate resources more effectively.


The authors’ approach offers several advantages over traditional methods of assessing ransomware risk. For one, it allows for the integration of large amounts of unstructured data, which is often difficult to analyze using traditional techniques. Additionally, the model’s ability to learn from patterns in ransomware group behavior enables it to adapt to changing threat landscapes.


While there are certainly limitations to this study, its results demonstrate the potential of LLMs in enhancing our understanding and mitigation of ransomware threats. As the cyber landscape continues to evolve, researchers and practitioners alike will need to stay ahead of the curve by embracing innovative approaches like this one.


The authors’ work highlights the importance of data-driven decision making in cybersecurity and underscores the need for continued investment in research and development.


Cite this article: “Uncovering Ransomware Risk: A Machine Learning Approach to Predicting Attacks”, The Science Archive, 2025.


Ransomware, Machine Learning, Cybersecurity, Risk Assessment, Data-Driven Decision Making, Unstructured Data, Large Language Models, Threat Intelligence, Predictive Modeling, Cyber Threat Landscape


Reference: Spencer Massengale, Philip Huff, “Assessing and Prioritizing Ransomware Risk Based on Historical Victim Data” (2025).


Leave a Reply