Tuesday , June 24 2025
Ransomware
Ransomware red button on keyboard, 3D rendering

Corvus threat intel report
Ransomware Attacks Up More Than 95% Over 2022

In its Q2 2023 Global Ransomware Report, Corvus noted a significant resurgence in global ransomware attacks, which has continued through the third quarter. Now, with two months remaining in the year, the number of ransomware victims in 2023 has already surpassed what was observed for 2021 and 2022. If the trajectory continues, 2023 will be the first year with more than 4,000 ransomware victims posted on leak sites (2,670 in 2022).

           Corvus Threat Intel report

2023 has already seen more ransomware victims than all of 2021 and 2022 combined. If this trend continues, there could be over 4,000 ransomware victims posted on leak sites this year.

Kaspersky found “SparkKitty” Malware on Google Play, Apple App Store

Kaspersky found a new mobile malware dubbed SparkKitty in Google Play and Apple App Store apps, targeting Android and iOS....
Read More
Kaspersky found “SparkKitty” Malware on Google Play, Apple App Store

OWASP AI Testing Guide Launched to Uncover Vulns in AI Systems

OWASP has released its AI Testing Guide, a framework to help organizations find and fix vulnerabilities specific to AI systems....
Read More
OWASP AI Testing Guide Launched to Uncover Vulns in AI Systems

Axentec Launches Bangladesh’s First Locally Hosted Tier-4 Cloud Platform

In a major milestone for the country’s digital infrastructure, Axentec PLC has officially launched Axentec Cloud, Bangladesh’s first Tier-4 cloud...
Read More
Axentec Launches Bangladesh’s First Locally Hosted Tier-4 Cloud Platform

Hackers Bypass Gmail MFA With App-Specific Password Reuse

A hacking group reportedly linked to Russian government has been discovered using a new phishing method that bypasses two-factor authentication...
Read More
Hackers Bypass Gmail MFA With App-Specific Password Reuse

Russia detects first SuperCard malware attacks via NFC

Russian cybersecurity experts discovered the first local data theft attacks using a modified version of legitimate near field communication (NFC)...
Read More
Russia detects first SuperCard malware attacks via NFC

Income Property Investments exposes 170,000+ Individuals record

Cybersecurity researcher Jeremiah Fowler discovered an unsecured database with 170,360 records belonging to a real estate company. It contained personal...
Read More
Income Property Investments exposes 170,000+ Individuals record

ALERT (CVE: 2023-28771)
Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs

GreyNoise found attempts to exploit CVE-2023-28771, a vulnerability in Zyxel's IKE affecting UDP port 500. The attack centers around CVE-2023-28771,...
Read More
ALERT (CVE: 2023-28771)  Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs

CISA Flags Active Exploits in Apple iOS and TP-Link Routers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included two high-risk vulnerabilities in its Known Exploited Vulnerabilities (KEV)...
Read More
CISA Flags Active Exploits in Apple iOS and TP-Link Routers

10K Records Allegedly from Mac Cloud Provider’s Customers Leaked Online

SafetyDetectives’ Cybersecurity Team discovered a public post on a clear web forum in which a threat actor claimed to have...
Read More
10K Records Allegedly from Mac Cloud Provider’s Customers Leaked Online

Canada 2nd largest airlines “WestJet” investigates cyberattack disrupting internal systems

WestJet, Canada's second-largest airline, is looking into a cyberattack that has affected some internal systems during its response to the...
Read More
Canada 2nd largest airlines “WestJet” investigates cyberattack disrupting internal systems
     Corvus Threat Intel report
Note that this is not the complete picture. Victims who are listed on leak sites usually do not pay or delay paying a ransom. However, a significant portion of victims, estimated to be between 27% – 41%, promptly pay the demands of threat actors and therefore are not seen on leak sites.
As a result, the total number of businesses affected by ransomware could be approximately 5,500 – 7,000 in 2023.

Factors Contributing to the Global Ransomware Surge

CL0P Mass Exploits Peaked:

CL0P, a previously quiet ransomware group, became active in Q1 by exploiting GoAnywhere file transfer software and impacting over 130 victims. In Q2, they targeted MOVEit file transfer software using a zero-day vulnerability, affecting 264 victims. This single vulnerability accounted for 9% of Q2’s total and 13% of Q3’s victims, significantly contributing to an increasing victim count.

However, even without CL0P, ransomware numbers increased by 5% compared to the previous quarter and 70% compared to the previous year in Q3.

The graph below illustrates the significant impact of a single group like CL0P, which was once relatively quiet.

Prior to 2023, CL0P only had a small number of ransomware victims. Now, they make up a considerable share of the total. A single opportunity for mass exploitation can lead to record-breaking results for a ransomware group.

        Corvus Threat Intel report
The grey bars show the activity of ransomware groups, excluding CL0P. These bars have been increasing steadily in 2023. Even without CL0P, ransomware activity is increasing.
Each quarter of this year has been higher than the previous one. Based on past trends, Q4 is expected to be worse than Q3.
     Corvus Threat Intel report
LockBit and ALPHV (BlackCat) reduced the number of victims on their leak sites by around 50% from April to July 2023. However, the latest numbers from late Q3 and early Q4 indicate that ransomware groups are returning to their usual activities and are expected to cause more harm in Q4.
  Corvus Threat Intel report

 

 

Check Also

AI Vulnerability

Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Action

Aim Labs discovered a zero-click AI vulnerability named “EchoLeak” in Microsoft 365 Copilot and reported …

Leave a Reply

Your email address will not be published. Required fields are marked *