Wednesday , December 25 2024
Ransomware
Ransomware red button on keyboard, 3D rendering

Corvus threat intel report
Ransomware Attacks Up More Than 95% Over 2022

In its Q2 2023 Global Ransomware Report, Corvus noted a significant resurgence in global ransomware attacks, which has continued through the third quarter. Now, with two months remaining in the year, the number of ransomware victims in 2023 has already surpassed what was observed for 2021 and 2022. If the trajectory continues, 2023 will be the first year with more than 4,000 ransomware victims posted on leak sites (2,670 in 2022).

           Corvus Threat Intel report

2023 has already seen more ransomware victims than all of 2021 and 2022 combined. If this trend continues, there could be over 4,000 ransomware victims posted on leak sites this year.

CVE-2024-9474
Sophisticated backdoor found in Palo Alto Networks firewalls: Northwave research

Northwave Cyber Security has found a sophisticated backdoor, LITTLELAMB.WOOLTEA, targeting Palo Alto Networks firewalls. A backdoor was found during a...
Read More
CVE-2024-9474  Sophisticated backdoor found in Palo Alto Networks firewalls: Northwave research

New G-Door Vul Allow Hackers Bypass Microsoft 365 Security With Google Docs

A newly discovered vulnerability called "G-Door" enables malicious actors to bypass Microsoft 365 security by exploiting unmanaged Google Docs accounts....
Read More
New G-Door Vul Allow Hackers Bypass Microsoft 365 Security With Google Docs

CVE-2024-53961
Adobe alerts of critical ColdFusion bug with PoC exploit available

Adobe has issued urgent security updates for ColdFusion versions 2023 and 2021 to fix a critical vulnerability (CVE-2024-53961). This flaw...
Read More
CVE-2024-53961  Adobe alerts of critical ColdFusion bug with PoC exploit available

Splunk targets Bangladeshi market: Investing in local talent

Splunk, a unified security and observability platform turn its focuses on Bangladeshi market. On Monday (23 December) Splunk's local partner...
Read More
Splunk targets Bangladeshi market: Investing in local talent

Critical PHP Zero-Day Vulnerability found in Craft CMS To Gain RCE

A major security flaw in Craft CMS, a popular PHP content management system, has been found, enabling unauthenticated remote code...
Read More
Critical PHP Zero-Day Vulnerability found in Craft CMS To Gain RCE

For US$2.6bn, Mastercard acquires threat intelligence firm Recorded Future

Mastercard has completed its acquisition of Recorded Future, an AI-based threat intelligence provider. Mastercard has acquired the company for $2.65...
Read More
For US$2.6bn, Mastercard acquires threat intelligence firm Recorded Future

Eight New ICS Advisories released by CISA

CISA has released eight advisories on vulnerabilities in Industrial Control Systems (ICS). These vulnerabilities affect essential software and hardware in...
Read More
Eight New ICS Advisories released by CISA

Authority Denies
Hacker claim ransomware attack on Indonesia’s state bank BRI

Bank Rakyat Indonesia (BRI), the largest state bank by assets, has assured customers that their data and funds are secure...
Read More
Authority Denies  Hacker claim ransomware attack on Indonesia’s state bank BRI

London-based company “Builder.ai” reportedly exposed 1.2 TB data

Cybersecurity researcher Jeremiah Fowler reported to Website Planet that he found a non-password-protected 1.2 TB dataset containing over 3 million...
Read More
London-based company “Builder.ai” reportedly exposed 1.2 TB data

(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)
Sophos resolved 3 critical vulnerabilities in Firewall

Sophos has fixed three separate security vulnerabilities in Sophos Firewall.  The vulnerabilities CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729 present major risks, such...
Read More
(CVE-2024-12727, CVE-2024-12728, CVE-2024-12729)  Sophos resolved 3 critical vulnerabilities in Firewall
     Corvus Threat Intel report
Note that this is not the complete picture. Victims who are listed on leak sites usually do not pay or delay paying a ransom. However, a significant portion of victims, estimated to be between 27% – 41%, promptly pay the demands of threat actors and therefore are not seen on leak sites.
As a result, the total number of businesses affected by ransomware could be approximately 5,500 – 7,000 in 2023.

Factors Contributing to the Global Ransomware Surge

CL0P Mass Exploits Peaked:

CL0P, a previously quiet ransomware group, became active in Q1 by exploiting GoAnywhere file transfer software and impacting over 130 victims. In Q2, they targeted MOVEit file transfer software using a zero-day vulnerability, affecting 264 victims. This single vulnerability accounted for 9% of Q2’s total and 13% of Q3’s victims, significantly contributing to an increasing victim count.

However, even without CL0P, ransomware numbers increased by 5% compared to the previous quarter and 70% compared to the previous year in Q3.

The graph below illustrates the significant impact of a single group like CL0P, which was once relatively quiet.

Prior to 2023, CL0P only had a small number of ransomware victims. Now, they make up a considerable share of the total. A single opportunity for mass exploitation can lead to record-breaking results for a ransomware group.

        Corvus Threat Intel report
The grey bars show the activity of ransomware groups, excluding CL0P. These bars have been increasing steadily in 2023. Even without CL0P, ransomware activity is increasing.
Each quarter of this year has been higher than the previous one. Based on past trends, Q4 is expected to be worse than Q3.
     Corvus Threat Intel report
LockBit and ALPHV (BlackCat) reduced the number of victims on their leak sites by around 50% from April to July 2023. However, the latest numbers from late Q3 and early Q4 indicate that ransomware groups are returning to their usual activities and are expected to cause more harm in Q4.
  Corvus Threat Intel report

 

 

Check Also

Authority Denies
Hacker claim ransomware attack on Indonesia’s state bank BRI

Bank Rakyat Indonesia (BRI), the largest state bank by assets, has assured customers that their …

Leave a Reply

Your email address will not be published. Required fields are marked *