FBI research reports that victims of double ransomware attacks are now affected within 48 hours.

The FBI warns of a new trend in ransomware attacks, where multiple variants are executed on victim networks to encrypt systems in less than two days.
The FBI's warning is issued through a Private Professional Notification triggered by trends observed since July 2023.
The federal law enforcement agency explains that partners and those responsible for ransomware have been observed using two distinct variants in their attacks on victim organizations. The variants used in these double ransomware attacks include AvosLocker, Diamond, Hive, Karakurt, LockBit, Quantum, and Royal.
“This use of double ransomware variants resulted in a combination of data encryption, exfiltration, and financial losses from ransom payments,” the FBI reported.
“Second ransomware attacks against an already compromised system could significantly damage the victims' entities.”
48 hours between ransomware attacks
In contrast to the past, when ransomware groups usually required at least 10 days to carry out such attacks, now the overwhelming majority of ransomware incidents targeting the same victim occur within a mere 48‑hour timeframe, according to FBI data.
The CEO and Co‑Founder of Coveware, Bill Siegel, also told BleepingComputer that double encryption has existed for years, with some companies now facing re‑extortion threats again, as the attackers do not provide decryptors for either of the ransomware attacks.
Additionally, the Federal Bureau of Investigation (FBI) reports that since early 2022, many ransomware groups have begun adding new code to their data theft, destruction tools, and malware in order to evade detection.
In other incidents, malware with data-deleting functionality was set to lie dormant on compromised systems until a predetermined point in time. At that point, it would execute to destroy data on the targets' networks at periodic intervals.
Information source: bleepingcomputer.com
