The number of successful ransomware attacks, based on the number of victims placed on data, increased by 9% compared to last year. It is worth noting that this increase is occurring despite the actions of law enforcement authorities.

Symantec said it recorded 962 attacks in the first quarter of 2024 , compared to 886 in the same period last year.
Global law enforcement agencies collaborated and conducted multiple operations to make arrests, take down infrastructure, and undermine the credibility of the popular groups ALPHV/BlackCat and LockBit (in December 2023 and February 2024, respectively).
See also: Ransomware groups invest in custom malware
Although BlackCat has ceased operations , LockBit is still carrying out attacks.
Symantec explained that LockBit was the number one ransomware threat in the first quarter of 2024. The gang was behind more than 20% of attacks.
The ransomware groups that leaked the most data to leak sites were Qilin, Play, Phobos, Hunters, and Bianlian.
However, Symantec data shows that in Q1 2024, LockBit was first (32%), with Akira (14%) and Blacksuit (11%) following.
See also: EstateRansomware exploits vulnerability in Veeam software
Ransomware gangs exploit vulnerabilities
The report showed that exploiting known vulnerabilities continues to be the main driver for ransomware attacks. Symantec reported recent attacks exploiting CVE-2024-4577 in the PHP language.
Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a ransomware attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.
Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.
Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.

Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent ransomware attacks. Be sure to update your antivirus software regularly to ensure it is equipped to handle new threats.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Ransomware groups turn to defensive evasion
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to cyberattacks.
Source: www.infosecurity-magazine.com
