Rise in Active RaaS Groups Parallel Growing Victim Counts: Ransomware in 2H 2023

27 de marca de 2024

We cover the key trends that defined the ransomware threat landscape in the second half of 2023. Data from RaaS and extortion groups’ leak sites, open-source intelligence (OSINT) research, and the Trend Micro telemetry shows that LockBit, BlackCat, and Clop continued to rank among the active RaaS and extortion groups with the highest victim counts during this period.

Read More  

Ransomware: A type of malware that prevents or limits users from accessing their system, either by locking the system's screen or by locking the users' files unless a ransom is paid.   Read More
  • 06 de marca de 2024
    Our continuous surveillance and research of the threat landscape in 2023 showed patterns suggesting that as cybercriminals take advantage of the expanding attack surface, they are also learning to prioritize substance over size.
  • 20 de lutego de 2024
    The LockBit intrusion set, tracked by Trend Micro as Water Selkie, has one of the most active ransomware operations today. With LockBit’s strong malware capabilities and affiliate program, organizations should keep abreast of its machinations to effectively spot risks and defend against attacks.
  • 05 de grudnia de 2023
    W tym raporcie szczegółowo opisujemy główne punkty krajobrazu zagrożeń w nadchodzącym roku wraz z analizą i zalecanymi środkami łagodzącymi, opracowanymi przez zespół ekspertów ds. cyberbezpieczeństwa Trend Micro.
  • 05 de grudnia de 2023
    2024 is poised to be a hotbed for new challenges in cybersecurity as the economic and political terrains continue to undergo digitization and enterprises increasingly leverage artificial intelligence and machine learning (AI/ML), the cloud, and Web3 technologies. While these innovations are expected to lend a hand to organizations, they also provide opportunities for cybercriminals by promising big returns, more streamlined operations on wider impact zones, and more targeted victims.
  • 28 de listopada de 2023
    After the shutdown of its leak site in October, we look at how ransomware group Trigona operated during its period of activity and discuss how enterprises can fortify their defenses against similar threats.
  • 05 de października de 2023
    This report spotlights Akira, a novel ransomware family with highly experienced and skilled operators at its helm.
  • 21 de września de 2023
    We delve into three of the most active ransomware families that dominated the first half of 2023: LockBit, Clop, and BlackCat. This report features data from ransomware-as-a-service (RaaS) and extortion groups’ leak sites, Trend Micro’s open-source intelligence (OSINT) research, and the Trend Micro™ Smart Protection Network™, collected from Jan. 1 to June 30, 2023.
  • 08 de sierpnia de 2023
    Nasze dane zarządzania ryzykiem w powierzchniach ataku pokazują, że w pierwszej połowie 2023 r. najwięcej zdarzeń wykryto w Stanach Zjednoczonych, Brazylii i Indiach, a najczęściej atakowane branże to produkcja, opieka zdrowotna i nowoczesne technologie.
  • 15 de marca de 2023
    Backed by threat actors from Conti, Royal ransomware is poised to wreak havoc in the threat landscape, starting strong by taking a spot among the most prolific ransomware groups within three months since it was first reported. Combining new and old techniques and quick evolution, it is likely to remain a big player in the threat landscape in the future.