Cybersecurity

Lockbit Dominates Global Ransomware Landscape as Attacks Resurge Following Conti Restructuring and Emergence of New Threat Actors

The global cybersecurity landscape witnessed a significant resurgence in ransomware activity during the mid-summer of 2022, marking an end to a brief period of relative decline. According to the latest monthly threat pulse data released by the NCC Group, the volume of successful ransomware campaigns surged by 47 percent in July compared to the previous month. This resurgence is being spearheaded by established Ransomware-as-a-Service (RaaS) organizations, most notably Lockbit, alongside a new generation of threat actors emerging from the remnants of the disbanded Conti syndicate.

Researchers monitoring the dark web leak sites and scraping victim details have determined that 198 successful ransomware attacks were publicly documented in July 2022. While this figure represents a sharp incline from the figures recorded in June, it remains below the record-breaking heights seen in the early spring, where March and April each saw nearly 300 reported incidents. The current trend suggests that after a period of structural realignment among major cybercriminal syndicates, the threat landscape is returning to a state of high-intensity operations.

The Unchallenged Dominance of Lockbit 3.0

Lockbit has solidified its position as the world’s most prolific ransomware group, accounting for 62 successful compromises in July alone. This figure represents a nearly 20 percent increase from the 52 attacks attributed to the group in June. More significantly, Lockbit’s activity in July was more than double that of the second and third most active groups combined.

The group’s continued dominance coincides with the launch of "Lockbit 3.0," also known as "Lockbit Black." This iteration of their software introduced several innovations to the RaaS model, including the industry’s first "bug bounty" program for a ransomware collective. By offering rewards to security researchers and hackers who find vulnerabilities in their encryption code or infrastructure, Lockbit has adopted corporate-style quality assurance measures to ensure their tools remain effective against modern cybersecurity defenses.

Security analysts at the NCC Group have emphasized that Lockbit 3.0 currently represents the most significant threat to global organizations. The group’s ability to maintain a consistent operational tempo while simultaneously upgrading its technical capabilities has allowed it to capture a massive share of the ransomware market. Their affiliate-based model, where independent hackers use Lockbit’s tools in exchange for a percentage of the ransom, continues to attract high-level talent within the cybercriminal underground.

The Splintering of the Conti Empire

The recent volatility in ransomware statistics can be traced back to the upheaval within the Conti group, which was previously the world’s most dominant ransomware entity. In May 2022, the United States Department of State significantly increased the pressure on the group by offering a reward of up to $15 million for information leading to the identification or location of Conti’s leadership and co-conspirators.

This move followed a series of internal crises for Conti, including the "ContiLeaks" incident where a pro-Ukrainian member leaked the group’s internal Jabber logs and source code in response to Conti’s public support for the Russian invasion of Ukraine. The combination of intense law enforcement scrutiny and internal friction led to a formal restructuring of the organization.

The NCC Group report suggests that the dip in attacks observed in May and June was a "settling period" during which Conti’s members reorganized into smaller, more agile cells. By July, these new entities had successfully transitioned into their new modes of operation. The resurgence of attacks is essentially the result of these splinter groups becoming fully operational under new identities.

The Rise of Hiveleaks and BlackBasta

The primary beneficiaries of the Conti restructuring appear to be Hiveleaks and BlackBasta, which ranked as the second and third most active groups in July, respectively. Hiveleaks recorded 27 attacks, representing a staggering 440 percent increase from its June activity. BlackBasta followed with 24 attacks, a 50 percent increase over the same period.

Both groups have deep ties to the former Conti infrastructure. Hiveleaks, which operates as an affiliate-heavy RaaS, has long been associated with Conti’s operational methods. BlackBasta, on the other hand, is viewed by many researchers as a direct "replacement strain" or a successor brand designed to carry on Conti’s legacy without the "toxic" brand name that attracted federal bounties.

The rapid ascent of these two groups confirms that the "Conti" threat has not vanished but has instead evolved. By operating under different banners, these threat actors can diversify their tactics and reduce the risk of a single, coordinated law enforcement takedown affecting their entire operation. This fragmentation makes the threat landscape more complex for defenders, as they must now track multiple distinct sets of Tactics, Techniques, and Procedures (TTPs).

Chronology of the 2022 Ransomware Fluctuations

The fluctuations in ransomware volume throughout 2022 provide a clear timeline of how geopolitical events and law enforcement actions influence cybercriminal behavior:

  • March – April 2022: Ransomware activity reaches a peak, with nearly 300 attacks per month. Conti is at the height of its power, and Lockbit is rapidly scaling its infrastructure.
  • May 2022: The U.S. government announces the $15 million bounty on Conti. The group begins the process of "retiring" the Conti brand and dismantling its centralized infrastructure. Total global attacks begin to dip as actors go underground.
  • June 2022: Attacks reach a temporary low point. Lockbit launches "Lockbit 3.0" to fill the vacuum left by Conti. Former Conti members begin migrating to BlackBasta and Hiveleaks.
  • July 2022: The "resurgence" phase begins. Total attacks climb to 198. Hiveleaks and BlackBasta emerge as the primary successors to the Conti crown, while Lockbit maintains a massive lead.

Sector and Regional Impact Analysis

The July data highlights that no sector is immune to the ransomware threat, though certain industries remain more targeted than others. The industrial sector continues to be the primary target for these groups, followed by consumer cyclicals and technology. The rationale behind targeting industrial firms often lies in the critical nature of their operations; downtime in manufacturing or logistics can result in massive financial losses, making these victims more likely to pay high ransoms to restore services quickly.

Geographically, North America remains the most targeted region, accounting for nearly half of all documented attacks. Europe follows as the second most targeted area. This distribution is largely driven by the "Big Game Hunting" strategy employed by groups like Lockbit and BlackBasta, who prioritize organizations with high annual revenues located in Western jurisdictions.

Technical Implications and "Double Extortion"

A defining characteristic of the current ransomware surge is the universal adoption of the "double extortion" model. In this scenario, threat actors not only encrypt the victim’s files but also exfiltrate sensitive data before the encryption process begins. If the victim refuses to pay for the decryption key, the attackers threaten to leak the stolen data on their public "shame sites."

Groups like Lockbit and Hive have refined this process. They often provide "previews" of stolen data to increase pressure on executives. Furthermore, some groups have experimented with "triple extortion," which includes launching Distributed Denial of Service (DDoS) attacks against the victim’s website or contacting the victim’s clients and employees directly to inform them that their data has been compromised.

Official Responses and Strategic Outlook

Law enforcement agencies and cybersecurity firms are increasingly focused on disrupting the financial incentives of the RaaS model. The U.S. Treasury’s Office of Foreign Assets Control (OFAC) has issued several advisories warning that paying ransoms to sanctioned entities—which may include certain Russian-linked groups—can result in legal penalties for the victims.

However, the NCC Group’s findings suggest that the threat actors are proving resilient to these pressures. The ability of Conti to successfully "rebrand" into Hiveleaks and BlackBasta demonstrates the difficulty of permanently dismantling these networks. When one brand becomes too targeted by law enforcement, the operators simply shift their assets, code, and personnel to a new name.

Looking ahead to the remainder of 2022, analysts predict that the volume of attacks will continue to climb. The "restructuring" phase appears to be complete, and the new entities are now operating at full capacity. Furthermore, the increasing professionalism of these groups—evidenced by Lockbit’s bug bounty program—suggests that the technical barrier to entry for cybercriminals is lowering while the sophistication of the malware is increasing.

Organizations are advised to move beyond traditional perimeter defenses and adopt a "Zero Trust" architecture. With the rise of RaaS, the frequency of attacks is no longer dependent on the skill of a few elite hackers but on the availability of automated tools that can be used by hundreds of affiliates. As the NCC Group report concludes, the current surge is not a temporary spike but a return to a dangerous baseline, with Lockbit 3.0 and the Conti offshoots remaining the primary architects of global digital disruption.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Jar Digital
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.