Although the results of law enforcement actions against the ransomware-as-a-service Alphv/BlackCat and LockBit have not yet fully taken shape, the suspension of the Qakbot botnet in August 2023 had one obvious result: ransomware partners have switched to exploiting vulnerabilities as the primary method of malware delivery.
See also: Microsoft Teams: Ransomware access broker steals accounts through phishing

The change is obvious to the Symantec Teams, but unfortunately it was not accompanied by a decrease in the number of ransomware victims.
Analysis of data from ransomware leak sites reveals that attackers managed to hit significantly more victims last year (4,700) compared to 2022 (2,800), they pointed out.
Constantly changing techniques
One of the hallmarks of successful ransomware groups is their ability to adapt their techniques to changing circumstances. When one door closes, they look for – and find – another.
For example, malicious macro-enabled documents long served as the primary means of ransomware delivery, until Microsoft implemented default protections that made this approach significantly less successful and forced them to change it.
The researchers pointed out other current trends related to ransomware attacks: the use of vulnerable drivers by attackers (e.g., to disable security software), legitimate remote desktop tools (AnyDesk, Atera, etc.), customized data theft tools (e.g., Lockbit's StealBit), and abuse of built-in Windows (e.g., Esentutl, DPAPI) to steal credentials.
See also: BianLian ransomware group stole data from Save The Children
Symantec threat detectors also noticed a strange phenomenon that suggests a skill imbalance between Lockbit and Alphv/Blackcat collaborators.
Alphv/BlackCat appears to be implementing an exit scam and defrauding some of its associates, while the main operator of the LockBit ransomware group is trying to reassure associates who were intimidated by law enforcement action to stay and continue collaboration .

Meanwhile, the (relative) gap in the ransomware landscape created by the problems of the two groups above, according to cybersecurity firm RedSense, has been partially filled by Akira ransomware and related groups such as Zeon.
“In December, we obtained reliable primary information from sources (…), suggesting that Zeon operates as an elite team of pentesters for both Akira and LockBit, with the latter being their primary target,” said RedSense co-founder Yelisey Bohuslavskiy.
See also: Epic Games: Mogilevich hackers say they stole data
What are the key functions of Ransomware-as-a-Service?
Ransomware-as-a-Service (RaaS) is a model used in cyberspace, where hacking groups provide ransomware services to third parties. The core functions of RaaS include the creation, distribution, and management of ransomware attacks. Creation refers to the development of the ransomware software. RaaS providers create and deliver customized ransomware software that can be used for attacks. This software is often easy to use and does not require specialized knowledge. RaaS providers can use various techniques, such as phishing emails, malicious downloads, and drive-by downloads, to distribute the software to victims. RaaS providers also provide tools and services for monitoring the performance of attacks, managing ransom payments, and communicating with victims.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: helpnetsecurity
