Every week, an organization is hit by ransomware, but a new report from security research group eSentire and dark web researcher Mike Mayes points out that the incidents we see in the news are only a small fraction of the true number of victims of such attacks. Ransomware Report states that in 2021 alone, six ransomware gangs breached 292 organizations between January 1 and April 31.
The report estimates that hackers managed to raise at least $45 million from these attacks, while also describing many incidents that have not been made public.
The eSentire team and Mayes focused on the ransomware gangs of Ryuk/Conti, Sodin/REvil, CLOP, DoppelPaymer, DarkSide, and Avaddon.

Read also: How long do ransomware groups stay on networks before being detected?
Each gang focuses on specific industries and regions of the world, according to the report. The Ryuk/Conti has attacked 352 organizations since 2018 and 63 this year, primarily targeting construction and transportation companies.
Dozens of their victims have not been reported, but among the most notable organizations attacked include the Broward County School District and the French company “CEE Schisler” – both of which did not pay the exorbitant ransoms demanded, according to the report.
In addition to the construction industry, the gang carried out attacks on small government IT systems across the US in 2020, including Jackson County, Georgia; Riviera Beach, Florida; and LaPorte County , Indiana. All three governments paid ransoms, ranging from $130,000 to nearly $600,000. The gang also spent much of 2020 carrying out attacks on local hospitals.
See also: Double encryption: The new technique used by ransomware groups
Like the Ryuk/Conti gang, the hackers behind the Sodin/REvil also target healthcare organizations, while also attempting to attack laptop manufacturers. Of their 161 victims, 52 were hit in 2021, including Acer and Quanta, two of the world’s largest technology manufacturers.
The hackers demanded a ransom of $50 million from Quanta , which makes Apple laptops . The company refused, and the Sodin/REvil gang leaked detailed blueprints of an Apple product in response. The gang then threatened to leak more documents. Apple has not spoken about the hack since.

DoppelPaymer /BitPaymer is known for targeting government institutions and schools. The FBI issued a statement specifically about the ransomware in December, noting that it is being used to attack critical infrastructure, such as hospitals and emergency services.
The report adds that most of the 59 victims the gang lists this year have not been reported, except for the Illinois attorney general's office, which was attacked on April 29.
The Clop ransomware gang has focused its efforts on exploiting a vulnerability in Accellion ’s file transfer system . The eSentire team and Mayes explain that the gang exploited the vulnerability and hit the University of California, Flagstar Bank, global law firm Jones Day, Canadian jet manufacturer Bombardier, Stanford University, Dutch oil giant Royal Shell, the University of Colorado, the University of Miami, fuel company RaceTrac, and more .
The DarkSide has been in the news a lot lately for its attack on Colonial Pipeline, which sparked a political storm in the US and caused gas station outages in some cities along the East Coast. It is one of the newest of the top ransomware gangs to emerge in late 2020, according to the report. It has claimed 59 victims since November and 37 this year alone.
Suggestion: New threat: Ransomware attacks with triple blackmail
The report notes that the DarkSide gang is one of the few that operates as a ransomware-as-a-service, outsourcing the attack to partners and then splitting the ransom. Last week, the gang announced it was shutting down its operation due to increased law enforcement scrutiny.

The ransomware has been involved in several attacks against energy producers, such as one of Brazil's largest electricity companies, Companhia Paranaense de Energia, which was hit in February.
Another gang studied is Avaddon, which was in the spotlight this week for its attack on the major European insurance company “AXA.” The attack was notable because AXA provides dozens of companies with cyber insurance.
In addition to AXA, the gang has also attacked 46 organizations this year and operates as a ransomware-as-a-service operation like DarkSide. The report explains that the gang is notable for including a countdown clock on its dark web site and for the added threat of a DDoS attack if victims refuse to pay the ransom.

The list of victims of the border closure includes healthcare organizations such as Capital Medical Center in Olympia, Washington, and Bridgeway Senior Healthcare in New Jersey.
The eSentire team and Mayes added that the large number of unreported attacks indicates that these gangs are “destroying many more entities than the public realizes.
Another disappointing finding is that no industry is immune to the scourge of ransomware. Finally, the report highlights that these debilitating attacks are occurring across all regions and sectors , and it is imperative that all companies and private organizations implement protective security measures to mitigate the damage resulting from a ransomware attack.
Information source: zdnet.com
