Lockbit Dominates as Ransomware Attacks Surge, Conti Offshoots Rise

The landscape of cyber threats is once again being reshaped by a resurgent wave of ransomware attacks, with the Lockbit group emerging as the most prolific offender this summer. Data released by NCC Group reveals a significant uptick in ransomware activity, particularly driven by established Ransomware-as-a-Service (RaaS) operations. This surge follows a recent dip, indicating a dynamic and persistent threat from organized cybercriminal syndicates.
NCC Group’s "Monthly Threat Pulse" for July 2022 meticulously tracked the activities of various ransomware gangs by actively monitoring their public leak sites and collecting victim data as it was disclosed. The findings paint a stark picture: Lockbit was responsible for an overwhelming 62 attacks in July alone. This figure not only represents a notable increase from the previous month but also more than doubles the combined total of the second and third most active groups. The report explicitly identifies Lockbit 3.0 as maintaining its position as the preeminent threat, urging all organizations to remain acutely aware of its capabilities and modus operandi.
Following Lockbit in terms of activity were two groups with direct lineage to the notorious Conti syndicate: Hiveleaks and BlackBasta. Hiveleaks recorded 27 attacks, while BlackBasta was responsible for 24. The rapid escalation of these groups’ activities is particularly striking. Hiveleaks, in particular, witnessed an astonishing 440 percent increase in its attack volume since June, while BlackBasta saw a still-significant 50 percent rise. This concurrent and dramatic ascent of these Conti-affiliated groups suggests a potential direct correlation between the restructuring of a major cybercrime entity and the subsequent proliferation of its offshoots in the threat landscape.
Overall, NCC Group’s analysis identified 198 successful ransomware campaigns in July, marking a substantial 47 percent increase from June. While this upward trajectory is concerning, it is important to note that it has not yet reached the peak levels observed in the spring of 2022, when both March and April saw nearly 300 ransomware campaigns each. This suggests a period of adaptation and reorganization within the ransomware ecosystem, potentially in response to external pressures.
The Shifting Sands of Cybercrime: Conti’s Legacy and the Rise of Offshoots
The current resurgence in ransomware activity, and the concurrent rise of Hiveleaks and BlackBasta, is intrinsically linked to the recent strategic realignments within the cybercrime world, specifically concerning the Conti group. In May 2022, the United States government intensified its efforts against Russian-linked cybercriminal organizations by offering substantial rewards, up to $15 million, for actionable intelligence that could lead to the apprehension of individuals associated with the Conti ransomware variant. At that time, Conti was widely recognized as the world’s leading ransomware gang, commanding significant influence and resources within the illicit cyber economy.
The impact of these increased enforcement efforts and bounties appears to have been a catalyst for significant structural changes within Conti and its affiliated operations. NCC Group researchers theorize that threat actors operating under the Conti umbrella were undergoing internal restructuring. This period of transition likely involved the dissolution of the core Conti entity and the subsequent re-emergence of its constituent elements and affiliates under new banners. As these threat actors have "begun settling into their new modes of operating," their combined compromise figures have consequently increased.
Hiveleaks and BlackBasta are understood to be direct products of this Conti restructuring. The report clarifies that Hiveleaks is associated with Conti as an affiliate, essentially a ransomware operator who uses the RaaS platform provided by the Conti group. BlackBasta, on the other hand, is identified as a "replacement strain," suggesting a more direct evolution or rebranding of Conti’s core ransomware technology and operations. The swiftness with which these new entities have established themselves and scaled their operations underscores the adaptability and resilience of organized cybercriminal networks.
The authors of the NCC Group report speculate that with Conti having effectively "split in two," referring to the emergence of these distinct but related entities, further increases in ransomware attack figures are probable as the threat landscape moves into August and beyond. This fragmentation, ironically, appears to have amplified the overall ransomware threat by distributing capabilities and potentially reducing the single point of failure that a monolithic organization like Conti represented.
Understanding the Resurgence: Factors Fueling the Rise
The increase in ransomware attacks is not a monolithic event but rather a confluence of several factors. The RaaS model, which has been a cornerstone of ransomware operations for years, continues to be a potent enabler. RaaS allows developers of ransomware to lease their malicious software to affiliates, who then conduct the actual attacks. This model lowers the barrier to entry for aspiring cybercriminals and allows the core developers to profit from a wide network of operatives without directly engaging in the high-risk activities of infection and data exfiltration.
The "old ransomware-as-a-service (RaaS) groups" mentioned in the NCC Group report refer to the enduring nature of these business models. Despite law enforcement efforts and takedowns of specific groups, the underlying infrastructure and operational frameworks of RaaS often persist, adapting to new threats and challenges. The Conti restructuring exemplifies this adaptability, with its core components and personnel likely migrating to new ventures.
The specific rise of Hiveleaks and BlackBasta can be further contextualized by examining their operational methods. While detailed technical analyses are often proprietary and released gradually, their association with Conti suggests they inherit a significant operational playbook, including sophisticated evasion techniques, potent encryption algorithms, and established extortion strategies. The rapid growth in their attack numbers indicates they are effectively leveraging these inherited capabilities and potentially expanding their affiliate networks.
The fact that these groups are emerging from the ashes of Conti highlights the challenges in dismantling sophisticated cybercrime networks. Unlike traditional criminal organizations, cybercrime groups can operate across borders with relative anonymity, making prosecution and asset seizure exceptionally difficult. The financial incentives are immense, with ransomware payouts often reaching millions of dollars, creating a powerful draw for individuals with technical skills and a willingness to engage in illicit activities.
Implications for Organizations and the Broader Cybersecurity Landscape
The sustained and increasing threat posed by Lockbit, Hiveleaks, BlackBasta, and other ransomware groups carries significant implications for organizations across all sectors. The rise of Lockbit 3.0, in particular, signals a need for heightened vigilance. Its consistent dominance suggests a robust infrastructure, effective attack methodologies, and a persistent ability to evade detection and mitigation efforts. Organizations must ensure their defenses are not only robust but also adaptable to the evolving tactics of these advanced persistent threats.
The emergence of Conti offshoots also presents a complex challenge. The fragmentation of a major threat actor can lead to a more diffuse, yet potentially more pervasive, threat landscape. Each new iteration or affiliate group may adopt slightly different tactics or target different sectors, requiring a broader understanding of the evolving threat matrix. Security teams need to be aware that threats previously associated with a single entity may now manifest through multiple, seemingly independent, groups.
Furthermore, the persistent use of RaaS models underscores the importance of a multi-layered security approach. While technical defenses such as firewalls, intrusion detection systems, and endpoint protection are crucial, they are often insufficient on their own. Security awareness training for employees is paramount, as phishing and social engineering remain primary entry vectors for ransomware. Regular data backups, stored offline and immutably, are a critical last line of defense to ensure business continuity in the event of a successful attack.
The financial implications of ransomware attacks extend beyond the immediate ransom payment. They can include significant costs associated with incident response, system remediation, reputational damage, legal fees, and potential regulatory fines. The longer an organization remains compromised, the higher these costs escalate. Therefore, proactive threat intelligence, robust security postures, and comprehensive incident response plans are not merely best practices but essential components of modern business resilience.
The efforts by governments to disrupt these criminal enterprises, such as the bounties offered for Conti-related information, are vital. However, the continuous adaptation of these groups demonstrates the need for ongoing international cooperation and a multi-pronged approach that combines law enforcement, intelligence sharing, and private sector cybersecurity collaboration. The battle against ransomware is an ongoing one, requiring constant vigilance and a commitment to staying ahead of the evolving threat landscape.
Looking Ahead: A Dynamic and Evolving Threat
As the cybersecurity community continues to analyze the implications of the July threat pulse, the outlook for the coming months remains one of heightened caution. The established dominance of Lockbit, coupled with the rapid ascent of Conti’s successor groups, suggests that ransomware will remain a significant and evolving threat. Organizations are strongly advised to review and enhance their cybersecurity strategies, focusing on proactive defense, rapid detection, and resilient recovery capabilities. The dynamic nature of cybercrime demands a continuous commitment to adaptation and preparedness.






