Ransomware has emerged as one of the most devastating cybercrime threats in the modern digital landscape, with criminal organizations operating sophisticated, multi-billion dollar operations targeting critical infrastructure in multiple countries.
See also: Cephalus Ransomware: Exploits RDP for Home Access

Between 2020 and 2022, ransomware groups carried out over 865 recorded attacks against organizations in Australia, Canada, New Zealand, and the United Kingdom, using advanced cryptographic techniques that encrypt data systems while demanding payments in cryptocurrency for decryption keys.
The evolution of these criminal operations has shifted from simple extortion via encryption to complex “double extortion” and “triple extortion” schemes, where attackers not only encrypt data but also threaten to sell or publicly disclose stolen information.
These groups compromise systems through various attack channels, including botnets, malicious freeware, and sophisticated phishing campaigns that exploit people's cognitive biases to gain initial access to target networks.
The emergence of Ransomware-as-a-Service (RaaS) models has fundamentally changed the cybercrime ecosystem, creating a distinction between core ransomware developers and their partners. Core teams focus on malware development, distribution infrastructure, processing victim payments, and maintaining leak websites, while partners handle the tactical elements of system compromise, ransomware deployment, and ransom negotiations.
AIC analysts found that this market-based relationship structure allows cybercriminals to easily move between different ransomware organizations, quickly adapting to law enforcement pressures and market opportunities.
See also: BQTLOCK: A new Ransomware-as-a-Service threat

Research conducted by the Australian Institute of Forensic Science reveals that Conti emerged as the most prolific ransomware organization, orchestrating 141 attacks over the three-year period, closely followed by the combined LockBit responsible for 129 attacks. The data shows that groups that adopt RaaS models and maintain business continuity over multiple years achieved significantly higher attack volumes than traditional ransomware operations.
The technical sophistication of modern ransomware operations extends far beyond simple file encryption, incorporating advanced persistence mechanisms and detection evasion techniques. Ransomware groups typically establish initial access through credential stuffing attacks, exploitation of unpatched vulnerabilities, or social engineering campaigns targeting remote desktop protocols.
Once inside target networks, attackers deploy lateral movement techniques using legitimate management tools such as PowerShell and Windows Management Instrumentation to evade detection. The persistence phase involves establishing multiple backdoors throughout the compromised network, often using legitimate system processes to maintain invisibility.
Groups like Conti and LockBit are implementing sophisticated detection protocols, systematically mapping the network architecture, identifying critical data repositories, and locating backup systems before deploying encryption payloads. The encryption process uses military-grade cryptographic algorithms, with many groups using hybrid encryption schemes that combine symmetric and asymmetric encryption to optimize both speed and security.
See also: Colt: Warlock ransomware group sells customer data

The industrial sector emerged as the top target across all countries analyzed, accounting for a total of 239 attacks. This targeting preference reflects both the critical nature of industrial operations and the sector’s vulnerability to operational disruption, making organizations more likely to pay ransoms to quickly restore production capabilities.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
