NCC Group Monthly Threat Pulse – July 2022


The ransomware threat scene continues to evolve following the disbanding of Conti, as ransomware attacks rose from 135 in June to 198 in July, representing a 47% increase, as reported by NCC Group’s Global Threat Intelligence team.



The escalation in ransomware attacks comes amidst the rise of several new threat actors, with newcomer Lockbit 3.0 taking the top spot followed closely by Conti-associated threat actors Hiveleaks and BlackBasta, that are settling into a new way of operating.


Meanwhile, Lazarus Group returns to prominence, following several multi-million-dollar cryptocurrency-focused attacks earlier this year.


SectorsSector trends remained consistent in July, with Industrials remaining the most targeted sector, as it made up a third (32%) of ransomware attacks, followed by Consumer Cyclicals (17%), and Technology (14%).


RegionsFrom a regional perspective, North America claimed the spot for most targeted region (42%), overtaking Europe (40%) for the first time in 2 months. The last time we saw North America as a top target was back in May.


Threat ActorsAs we moved into July, the phasing out of Lockbit 2.0 and transition to new variant Lockbit 3.0 looked to complete, as Lockbit 3.0 moved into pole position as the top ransomware variant this month with 52 incidents.


Meanwhile, the rise in prominence from Hiveleaks (27 victims), and BlackBasta (24 victims) may represent a possible regrouping of former Conti members as new, smaller factions.


Meanwhile, North Korea-backed APT Group Lazarus, have continued to make ripples in the cyber threat landscape following their $100 million crypto heist on Harmony’s Horizon Bridge in late June.


Spotlight on Lazarus GroupThis month, Lazarus Group claims the spotlight following a number of financial cybercrimes to aid the North Korean state earlier this year, including cryptocurrency thefts and suspected ransomware adoption. These include the $600 Million Cryptocurrency Heist on Axie Infinity, and the $100 Mill ..

Support the originator by clicking the read the rest link below.