HomeSecurityRansomHub surpasses LockBit as the most prolific Ransomware team

RansomHub surpasses LockBit as the most prolific Ransomware group

RansomHub is now the number one ransomware in terms of alleged successful attacks, surpassing LockBit, according to new data from Symantec.

See also: Underground ransomware behind the Casio attack?

RansomHub LockBit Ransomware Team

The security vendor's latest threat intelligence report for the third quarter of 2024, Ransomware: Threat Level Remains High in Third Quarter, is based on analysis of leak sites.

Overall, malicious actors carried out 1,255 attacks in the quarter, down slightly from 1,325 in the second quarter. However, the macro trend is that attacks are continuing, Symantec warned.

RansomHub only went live in February of this year, but it took the top spot in the third quarter with 191 victims posted on leak, a 155% increase over the second quarter.

"The group's rapid rise can be explained by its success in recruiting experienced affiliates to operate its ransomware-as-a-service, reportedly offering more attractive terms than rival groups," Symantec said.

See also: Rhysida Ransomware breached Axis healthcare systems

RansomHub's rise appears to have come at the expense of LockBit, which had three times as many successful attacks as its closest rival Qilin in the second quarter. It saw that number decline 88% quarter-over-quarter to 188 data breach disclosures in the third quarter, according to Symantec.

RansomHub surpasses LockBit as the most prolific Ransomware group

Qilin's presence is also on the rise, with the number of its victims increasing by 44% to 140 in the third quarter.

Symantec pointed out the difference between publicly reported attacks and the ransomware activity investigated by its own threat researchers. For example, LockBit accounted for just 7% of attacks investigated by Symantec in the third quarter, but claimed a 15%, while RansomHub's shares were 33% and 15% respectively.

In the case of RansomHub, the difference could potentially be explained by the fact that not all victims on ransomware-leaking websites – for example, if they pay their extortionists .

See also: Akira and Fog ransomware exploit Veeam vulnerability 

Ransomware groups are one of the most serious threats to cybersecurity , and individuals, holding it hostage in order to demand ransom. They often operate globally and use sophisticated strategies to evade detection by authorities. Ransomware attacks lead to significant financial losses and can impact critical operations, making preparedness and proactive action essential to address this growing risk.

Source: infosecurity-magazine

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS