Number of Ransomware Groups Surges: 73 Active Groups in 2024
A worrying increase in the number of ransomware groups reveals new trends in the threat landscape. In the first half of 2024, there was a sharp rise in the number of active ransomware groups, jumping from 46 groups in 2023 to 73. A new report by intelligence firm Searchlight Cyber highlights dramatic shifts in this map, with groups such as LockBit, Playcrypt, and RansomHub featuring prominently on the list of top attackers. These figures indicate that the fight against ransomware is far from over, and the need for preventive action has become more critical than ever.
The RaaS Model: Enabling Ransomware to Grow and Evolve
Renting ransomware kits to independent attackers is changing the rules of the game in the world of cybercrime. All leading ransomware groups operate under the “Ransomware-as-a-Service” (RaaS) model, in which they provide attack tools to independent users (“affiliates”) in exchange for a percentage of the profits. This model allows for an unprecedented expansion in the scope of operations, creating a broader and more effective attack infrastructure. However, this expansion also exposes large ransomware groups to increased risks, as it leads to greater visibility and scrutiny.
Increasing Complexity: How Can Businesses Protect Themselves?
The rise in ransomware threats necessitates a proactive approach to information security. Despite a decrease in the number of reported victims, the increase in the number of groups and advanced models presents significant security challenges. Security experts emphasize that the dismantling of large groups often leads to a rise in smaller groups that mimic their operations. Businesses are required to invest in advanced ransomware protection solutions, including enhanced monitoring and enforcement of backup processes and the continuous improvement of defensive capabilities.
Recommendations from IPV Security Experts:
* Upgrade existing security systems: Ensure all systems are up to date, including antivirus software and vulnerability detection mechanisms.
* Secure backup management: Maintain backups outside the corporate network with rapid recovery capabilities.
* Focus on access prevention: Reduce exposure by managing access according to the “Least Privilege” principle and strengthening multi-factor authentication (MFA).
* Active threat monitoring: Implement solutions for continuous monitoring and reporting of vulnerabilities and potential threats.
* Employee training: Provide employees with tools to identify phishing scams and other threats that serve as primary vectors for ransomware attacks.
In the face of the growing sophistication of ransomware groups, implementing these recommendations can significantly help mitigate risk. In conclusion, the rise in the number of ransomware groups increases the risk to businesses, and they must strengthen their defenses to counter these new threats.