The number of victims reported on gang ransomware leak sites reached “ unparalleled highs ” from March to June 2023, according to Secureworks ’ “ 2023 State of the Threat ” report .

So far, 2023 appears to be the year with the highest number of victims recorded on so-called “name and shame” websites since this practice began in 2019.
The Secureworks report, which presented information from July 2022 to June 2023, revealed that the mass exploitation of specific vulnerabilities was the main factor that led to many organizations and placed on data leak sites in the last four months:
- March – Fortra GoAnywhere, a bug exploited by the Clop ransomware gang
- May – Zimbra mail server, bug exploited by MalasLocker gang
- June – MOVEit Transfer, vulnerability used by the Clop gang
See also: Cuba ransomware: Attack on Wisconsin health department
Additionally, Secureworks said that a LockBit, going by the name GOLD MYSTIC, was the most active ransomware group during the 12-month period covered by the report, posting nearly three times the number of victims than the next most active group, ALPHV (BlackCat).
However, beyond the well-known groups, Secureworks revealed that new ransomware also claimed many victims from March to June 2023. This includes 8BASE which had nearly 40 victims on its leak site during June 2023.
The researchers acknowledged that leak sites alone do not provide a completely accurate picture of ransomware attacks, as they only list victims who have not paid the ransom. Furthermore, not all gangs use such sites.
See also: LockBit: Virginia school district reopens despite ransomware attack
The time it takes to develop ransomware has decreased
The report showed that the average time ransomware remained on systems was under 24 hours, representing a dramatic drop from 4.5 days in the previous 12 months. In 10% of cases, ransomware was deployed within five hours of initial access.
Cybercriminals know that companies are using more advanced detection methods and are speeding up their operations to reduce the chances of stopping ransomware before it can spread.

Ransomware: How is initial access achieved?
Secureworks observed that the two most common ways of initial access were scan-and-exploit (32%) and stolen credentials (32%), followed by phishing emails (14%).
Protection
Protection against ransomware attacks is today a primary requirement of cybersecurity and requires the adoption of multi-layered strategies:
See also: TeamCity RCE: Ransomware gangs exploit critical flaw
1. Install Reliable Antivirus Software
Installing reliable antivirus software is essential for identifying and dealing with malware before it can cause any damage. Modern programs offer advanced detection and response capabilities for threats like ransomware.
2. Backups
Creating and frequently updating copies of important data is one of the basic principles of cybersecurity. In the event that information is locked or threatened by ransomware, copies ensure that work can continue uninterrupted.
3. Staff Training
Familiarizing staff with attacker strategies and techniques is critical to protecting against ransomware. Training can enhance the ability to identify and avoid malicious links, software , and emails.
4. Timely Software Updates
Timely software updates are a fundamental factor in protecting against ransomware. These updates can patch vulnerabilities and add new layers of defense to combat the latest threats.
Overall, protecting against ransomware requires foresight and a continuous commitment to improving security practices. With proper preparation and ongoing monitoring, threats can be effectively addressed.
Source: www.infosecurity-magazine.com
