According to a new report from ZeroFox, LockBit ransomware continues to be the top threat when it comes to digital extortion.

Researchers found that LockBit was used in more than a quarter of global attacks ransomware and digital extortion (R&DE) from January 2022 to September 2023. The analysis showed that LockBit was responsible for 30% of all such attacks in Europe and 25% in North America.
However, ZeroFox said that the overall percentage of attacks represented by LockBit is on a downward trajectory. This is likely due to the increasing diversification of the R&DE landscape, with ransomware-as-a-service (RaaS) offerings lowering the barriers to entry for threat actors.
LockBit ransomware and North America
The researchers noted that LockBit was not used as frequently in attacks against North America compared to other regions, such as Europe. However, there was an increase in attacks during the time period mentioned above and it is believed that the percentage of victims will increase further by the end of 2023.
See also: Royal Mail: Spent £10 million on cybersecurity measures after LockBit attack
The industries most targeted by the LockBit gang in North America between January 2022 and September 2023 were manufacturing, construction, retail, legal and consulting services , and healthcare.

LockBit ransomware: Distribution and infection methods
The main techniques for distributing and deploying ransomware on victims' networks include:
Exploiting applications exposed on the Internet: Hackers exploit vulnerabilities in software that allowed remote code execution and gaining more privileges on vulnerable systems.
Phishing emails/messages: Affiliates of the LockBit gang used various lures in phishing attacks to gain access to victims. The malicious emails typically contained attachments and malicious links to infect victims.
External remote services: Threat actors leverage legitimate user credentials obtained through credential harvesting to gain access to external-facing remote working services.
Drive-by Compromise: Hackers gain access to systems through a user visiting a website, often targeting the user's web browser.
Use of valid accounts: Threat actors often compromise credentials to bypass access controls, create persistence, escalate privileges, and evade detection.
Although the percentage of R&DE attacks related to LockBit ransomware is decreasing, ZeroFox expects ransomware to remain one of the biggest threats to all types of organizations around the world.
See also: Allen & Overy: Law firm falls victim to LockBit attack
LockBit ransomware
The LockBit ransomware was first identified in September 2019. The ransomware is known for its speed of system compromise and its ability to spread within a compromised network.
This ransomware is said to be behind some recent major attacks, including those on Royal Mail, Boeing, and the Industrial and Commercial Bank of China (ICBC).

Protection against LockBit ransomware
To protect yourself from LockBit ransomware attacks, you should take a multi -layered approach . This includes installing strong antivirus software on all devices , regularly updating and patching software and operating systems, and using strong and unique passwords for all accounts. It is also important to regularly back up critical data and store it offline or on a separate network. Additionally, organizations should educate their employees about phishing emails and other social engineering tactics commonly used to distribute ransomware. By training employees to recognize and report suspicious emails or links, organizations can reduce the risk of falling victim to LockBit ransomware.
Another important LockBit ransomware protection measure is the implementation of network segmentation. By dividing the network into smaller, isolated segments, organizations can limit the spread of ransomware in the event that one segment is compromised. This can help limit the impact of an attack and prevent it from affecting the entire network.
See also: LockBit ransomware: Exploits Citrix Bleed vulnerability in attacks
It is also important to have an incident response planin place, which outlines the steps to take in the event of a ransomware attack. This plan should include procedures for isolating infected systems, notifying the appropriate authorities, and restoring data from backups.
Finally, organizations should stay up to date on the latest threats and security vulnerabilities.
By adopting a proactive and comprehensive approach to cybersecurity, organizations can significantly reduce the risk of falling victim to LockBit ransomware and other similar threats.
Source: www.infosecurity-magazine.com
