Palo Alto Networks published its semi-annual report on ransomware. From the Executive Summary:

Unit 42 monitors ransomware and extortion leak sites closely to keep tabs on threat activity. We reviewed compromise announcements from 53 dedicated leak sites in the first half of 2024 and found 1,762 new posts. This averages to approximately 294 posts a month and almost 68 posts a week. Of the 53 ransomware groups whose leak sites we monitored, six of the groups accounted for more than half of the compromises observed.

In February, we reported a 49% increase year-over-year in alleged victims posted on ransomware leak sites. So far, in 2024, comparing the first half of 2023 to the first half of 2024, we see an even further increase of 4.3%. The higher level of activity observed in 2023 was no fluke.

Activity from groups like Ambitious Scorpius (distributors of BlackCat) and Flighty Scorpius (distributors of LockBit) has largely fallen off due to law enforcement operations. However, other threat groups we track such as Spoiled Scorpius (distributors of RansomHub) and Slippery Scorpius (distributors of DragonForce) have joined the fray to fill the void.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Cyber-Attack on Evolve Bank Exposed Data of 7.6 Million Customers

July 9, 2024 0 Comments 0 tags

In a statement on Monday, Evolve confirmed the breach includes over 20,000 customers in Maine

Vulnerability disclosure policies eyed for federal contractors in Senate bill

August 13, 2024 0 Comments 0 tags

Federal contractors would be required to implement vulnerability disclosure policies that align with National Institute of Standards and Technology guidelines under a bipartisan Senate bill introduced last week. The Federal

BreachForums, a key English-language cybercrime forum, seized by the FBI

May 15, 2024 0 Comments 0 tags

The FBI, the Department of Justice and a range of international law enforcement agencies seized on Wednesday a notorious website used to buy and sell stolen and hacked data.  The