Lockbit, Blackcat, and clop prevail as top Raas Groups

POR ByondIT |

19 de octubre de 2023

Fuente original: Trendmicro, (ver original)

With contributions from Shingo Matsugaya

We delve into three of the most active ransomware families that dominated the first half of 2023: LockBitClop, and BlackCat.

Since 2022, our telemetry has consistently pointed to LockBit and BlackCat as two of the most detected RaaS providers.

LockBit’s level of pervasiveness is reflected in a joint cybersecurity advisory from The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), the Multi-State Information Sharing and Analysis Center (MS-ISAC), and other international security bureaus. According to the June 2023 report, one in every six ransomware attacks that targeted US government offices in 2022 was traced back to LockBit actors.

BlackCat also made waves in 2022 as it targeted several high-profile victims that include German oil companies and a European government. Today, all three ransomware families, including Clop, continue to be among the most prolific and evolutionary ransomware families in existence.

This report features data from ransomware-as-a-service (RaaS) and extortion groups’ leak sites, Trend Micro’s open-source intelligence (OSINT) research, and the Trend Micro™ Smart Protection Network™, collected from Jan. 1 to June 30, 2023. It should be noted that we did not include legacy ransomware families, or those that are not visibly active in the current threat landscape, in this report. Legacy ransomware family detections are also excluded from detection counts featured in this report.

Active RaaS, RaaS-related groups, and ransomware victims grew in the first half of 2023

We detected and blocked a total of 6,697,853 ransomware threats across email, URL, and file layers, based on data from our telemetry in the first six months of 2023. This number represents a slight decline of 3.64% compared to the last half of 2022, which had a total detection of 6,950,935.

After analyzing data from ransomware groups’ leak sites, or sites that published attacks on successfully compromised organizations but refused to pay ransom, we observed that the number of RaaS and RaaS-related groups grew by 11.3%.

We also noted that the number of victim organizations surged in the first half of 2023 at 2,001, a 45.27% increase compared to the last half of 2022.

Recomienda este artículo

Solicita una consultoría tecnológica personalizada para conocer el estado de tu empresa y detectar las áreas de mejora que te permitirán llevar tu negocio al siguiente nivel de la era digital

Explora nuevos horizontes tecnológicos

Database

Services

Ciber

Security

Executive

Services