Ransomware Watch: Top Targets and Threat Actors Revealed

Ransomware Watch: Top Targets and Threat Actors Revealed

Last week saw a significant uptick in ransomware activity, with the United States bearing the brunt of these attacks, according to insights from DARKFEED. They reported over 100 attacks targeting US entities, far surpassing other nations like the UK, Italy, France, and Germany, which each saw single-digit attack counts. This geographical focus highlights the persistent attractiveness of the US market for cybercriminals.

The healthcare and manufacturing sectors were particularly hard-hit, each experiencing 25% of the total reported attacks. Business services also featured prominently. This trend underscores the critical need for robust security measures in industries that handle sensitive data or are vital to economic operations. The concentration of attacks in these sectors suggests attackers are prioritizing high-impact targets.

When it comes to active threat groups, DARKFEED identified DragonForce as the most prolific actor, followed closely by Qilin and Lockbit. Akira and INC also remained active. With a total of 215 attacks logged, the threat landscape remains dynamic and demands constant vigilance from security teams.

What This Means For You

  • Given the high targeting of the Healthcare and Manufacturing sectors, organizations within these industries should prioritize strengthening their defenses against ransomware, focusing on data backup and recovery strategies, comprehensive endpoint protection, and rigorous employee security awareness training.
๐Ÿ”Ž
Is your vendor affected? Start hunting now. Search by organization or domain, set watchlist alerts, and get notified when your third parties are compromised.
Open Intel Bot โ†’

Related coverage

Showboat Linux Malware Targets Middle East Telecom with SOCKS5 Proxy

The Hacker News reports that a new Linux malware, named Showboat, has been actively deployed since mid-2022. This modular post-exploitation framework is designed to compromise...

threat-intelvulnerabilitymalwaretools
/SCW Vulnerability Desk /HIGH /⚑ 5 IOCs

Crypto Drainers Scale Wallet Theft via Phishing and Automation

Modern cryptocurrency drainers are not about breaking into wallets; they're about tricking users into approving malicious transactions. BleepingComputer reports that platforms like Lucifer DaaS are...

threat-inteldata-breachmalwarephishingbleepingcomputer
/SCW Research /MEDIUM

Law Enforcement Seizes 'First VPN' Service Used in Ransomware, Data Theft

International law enforcement has taken down "First VPN," a virtual private network service heavily implicated in ransomware and data theft operations. BleepingComputer reports the service...

threat-inteldata-breachmalwareransomwarebleepingcomputer
/SCW Research /MEDIUM