A new report from NCC Group plc shows ransomware attacks hit a record high in May, largely due to a significant resurgence in LockBit ransomware activities. According to the NCC Group 2024 Threat Intel report, global ransomware attacks increased by 32% month-over-month in May, reaching 470 incidents compared to 356 in April. This marks an 8% increase compared to May of last year.
The spike in attacks is primarily attributed to LockBit 3.0, the latest version of the notorious LockBit ransomware gang. After being dismantled by law enforcement in February, the group resurfaced just a week later, quickly becoming the most active ransomware group, responsible for 37% of all ransomware attacks in May. LockBit was implicated in 176 ransomware incidents during the month.
Other notable ransomeware players mentioned in the report for May included:
- Play ransomware group in second position with 32 attacks, for 7% of all attacks in the month
- RansomHub came in at third position with 22 attacks
- DAn0n, with 13 attacks. A newcomer to the field that uses a double-tap extortion method.
- Underground, which also uses double-tap extortion, was recorded to have undertaken 12 ransomware attacks during the month
- Arcus Media, with 11 attacks
The report noted that the majority (77%) of ransomware attacks in May targeted companies in North America and Europe, with a notable increase in attacks in South America, accounting for 8% of the total, a 60% rise from April.
By sector, industrial companies remained the most targeted, a trend ongoing since January 2021, with 143 attacks in May, up from 116 in April. The technology sector was the second most targeted, with 72 attacks, an increase from 49 the previous month.
Cigent CGO Brett Hansen had this to say:
“The only real way to end ransomware is to make it no longer profitable for the bad actors. Let me be clear, solutions already exist in the commercial sector to protect against these threats. In addition to instituting zero-trust access to your data, adding available real-time encryption can ensure that data is useless to the attacker, if they do get in. While you’re adding data protection, the use of invisible partitions can ensure your data is not accessed by intruders. Data at rest can also be data protected.”
What we see here is a game of “whack a mole”. Where law enforcement takes out LockBit only to have LockBit reappear in a new form. Like Mr. Hansen has said, this isn’t working. Thus organizations need to take security a lot more seriously and implant things that will make it way harder for threat actors to pwn them.
UPDATE: Rogier Fischer, CEO and Co-Founder, Hadrian add this comment:
“Ransomware groups like LockBit versions, and Conti before that, show how cybercriminal organizations evolve and change tracks, often rebranding or merging with other groups to stay operational despite law enforcement actions. The cybersecurity community have been dredging up evidence of their interconnectivity, as seen in the use of shared resources, such as Conti’s leaked source code being adopted by LockBit for its “LockBit Green” variant. Law enforcement actions, including arrests and website seizures, have disrupted these groups temporarily, but have not eliminated the threat entirely, as these groups quickly adapt and reconstitute their operations. What we need it continuous, coordinated international efforts to effectively combat the ever-evolving ransomware menace.”
Related
This entry was posted on June 21, 2024 at 8:34 am and is filed under Commentary with tags NCC Group. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
LockBit ransomware attacks in May up 665% over April
A new report from NCC Group plc shows ransomware attacks hit a record high in May, largely due to a significant resurgence in LockBit ransomware activities. According to the NCC Group 2024 Threat Intel report, global ransomware attacks increased by 32% month-over-month in May, reaching 470 incidents compared to 356 in April. This marks an 8% increase compared to May of last year.
The spike in attacks is primarily attributed to LockBit 3.0, the latest version of the notorious LockBit ransomware gang. After being dismantled by law enforcement in February, the group resurfaced just a week later, quickly becoming the most active ransomware group, responsible for 37% of all ransomware attacks in May. LockBit was implicated in 176 ransomware incidents during the month.
Other notable ransomeware players mentioned in the report for May included:
The report noted that the majority (77%) of ransomware attacks in May targeted companies in North America and Europe, with a notable increase in attacks in South America, accounting for 8% of the total, a 60% rise from April.
By sector, industrial companies remained the most targeted, a trend ongoing since January 2021, with 143 attacks in May, up from 116 in April. The technology sector was the second most targeted, with 72 attacks, an increase from 49 the previous month.
Cigent CGO Brett Hansen had this to say:
“The only real way to end ransomware is to make it no longer profitable for the bad actors. Let me be clear, solutions already exist in the commercial sector to protect against these threats. In addition to instituting zero-trust access to your data, adding available real-time encryption can ensure that data is useless to the attacker, if they do get in. While you’re adding data protection, the use of invisible partitions can ensure your data is not accessed by intruders. Data at rest can also be data protected.”
What we see here is a game of “whack a mole”. Where law enforcement takes out LockBit only to have LockBit reappear in a new form. Like Mr. Hansen has said, this isn’t working. Thus organizations need to take security a lot more seriously and implant things that will make it way harder for threat actors to pwn them.
UPDATE: Rogier Fischer, CEO and Co-Founder, Hadrian add this comment:
“Ransomware groups like LockBit versions, and Conti before that, show how cybercriminal organizations evolve and change tracks, often rebranding or merging with other groups to stay operational despite law enforcement actions. The cybersecurity community have been dredging up evidence of their interconnectivity, as seen in the use of shared resources, such as Conti’s leaked source code being adopted by LockBit for its “LockBit Green” variant. Law enforcement actions, including arrests and website seizures, have disrupted these groups temporarily, but have not eliminated the threat entirely, as these groups quickly adapt and reconstitute their operations. What we need it continuous, coordinated international efforts to effectively combat the ever-evolving ransomware menace.”
Share this:
Like this:
Related
This entry was posted on June 21, 2024 at 8:34 am and is filed under Commentary with tags NCC Group. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.