Ransomware gangs were very active during the last quarter of 2021, with security researchers detecting 722 attacks using 34 different ransomware variants.
This huge volume of attacks and the different ransomware create problems for potential victims, as it is difficult to identify the different tactics, etc.
See also: NetWalker ransomware associate extradited to US to face further charges

Compared to the third quarter of 2021, the fourth quarter saw an 18% higher volume of attacks. Compared to the second quarter, the increase is even greater, which shows that there is an overall trend of increasing ransomware attacks. After all, ransomware is one of the biggest threats in cyberspace and the attacks are not going to subside anytime soon.
Attackers and targets
According to an Intel 471, the most active ransomware groups during the fourth quarter of 2021 were LockBit 2.0 (29.7%), Conti (19%), PYSA (10.5%), and Hive (10.1%).
Compared to the previous quarter, only PYSA had a notable increase in activity, which was also reported in a report by NCC Group that examined November 2021 data.
In terms of targets, it seems that the attackers were mainly targeting North America. Specifically, according to the report, almost half of the attacks from the above ransomware gangs targeted users/businesses in this region. This was followed by Europe (30%). The remaining attacks (20%) were located in various regions around the world.
See also: REvil ransomware member extradited to US to stand trial for Kaseya attack
Focus shift
Compared to Q3 2021, there was a shift in the focus of hackers. The manufacturing sector saw a decline while targeting consumer and industrial products businesses increased. In addition, there was a significant increase in attacks on the healthcare and life sciences.

This shift may be due to the seasonal interest in shopping during Christmas and Black Friday/Cyber Monday, which makes the relevant targets more lucrative.
Additionally, healthcare is always an attractive target, but becomes more critical towards the end of the year, likely due to the winter season bringing higher virus transmission rates. Ransomware groups prefer to disrupt organizations/businesses at the worst possible time, to increase the chances of a quick response and the chances of ransom payments.
See also: Germany to companies: Do not use Kaspersky antivirus
For example, the FBI recently warned that ransomware gangs commonly target companies during mergers and acquisitions to exert further pressure during negotiations.
However, in many cases, ransomware gangs simply attack anyone and are not based on any industry or era.
Source: Bleeping Computer
