HomeSecurityLockBit 3.0 strengthens dominance of the ransomware ecosystem

LockBit 3.0 strengthens dominance of the ransomware ecosystem

The LockBit 3.0 ransomware appears to have led to a significant increase in documented ransomware attacks in July, with incidents increasing by 47% month-on-month, according to the most recent monthly threat data produced by NCC Group.

See also: AiTM attack targets Google G-Suite Enterprise users

LockBit 3.0 strengthens dominance of the ransomware ecosystem

LockBit’s operators released version 3.0 in late June with the tagline “Make Ransomware Great Again.” Among its new features are additional monetization tools, with payments now accepted in more cryptocurrencies than before, data recovery after payment, and even destruction. Most notably, the team is now running a bug bounty program and seems particularly eager to hear about any bugs in its code that could allow third parties to obtain the decryption tool.

Since its launch, LockBit has become the dominant ransomware strain identified as being actively used, accounting for 52 of the 198 NCC victims recorded in July, or 26% of the total. Two other groups – both affiliated with former linked – were also particularly active in July: Hiveleaks, which affected 27 organizations, and BlackBasta, which reached 24.

See also: Chrome's "Internet Download Manager" turned out to be adware

“This month’s Threat Pulse revealed some significant changes in ransomware attacks compared to June,” said NCC’s head of global threat intelligence, Matt Hull.

"Since Conti was dismantled, we have seen two new threat actors associated with the group – Hiveleaks and BlackBasta – take the top spot behind LockBit 3.0. It is reasonable to expect the number of ransomware attacks behind these two groups to continue to increase over the next two months.".

The North Korea-linked Lazarus persistent threat group (APT) has continued a cyber extortion campaign following a $100 million cryptocurrency heist at Harmony Horizon Bridge in late June and previous attacks, including a larger $600 million hack at Axie Infinity.

LockBit

Hull noted that the increased Lazarus was likely a result of the continued contraction of North Korea’s crippled economy, forcing the isolated regime to rely more on crime to obtain much-needed “hard currency.” As previously reported, this trend has led the U.S. to increase the reward money offered to anyone who can provide information on members of the Lazarus group.

As for other ransomware trends, the industries under attack remained stable in July, with industrial organizations remaining the most targeted, accounting for 32% of incidents observed by the NCC. This was followed by consumer cyclicals – which include automotive, entertainment and retail – at 17% and technology at 14%.

See also: Plex.tv data leak. Change passwords immediately!

The NCC found that the region most targeted for ransomware attacks was North America, where 42% of incidents were recorded during the period.

As always, it is important to note that vendor-generated threat data is proprietary and generally only reflects the conditions that particular vendor sees based on telemetry or collected by its incident response teams, so it may not be completely accurate.

Information source: computerweekly.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS