The Cyber Security Review | Thursday, December 29, 2022
Global Threat Intelligence team has revealed a 41 per cent increase in ransomware attacks this month as returning threat actor groups resurface and take the lead in November.
FREMONT, CA:According to analysis from NCC Group's Global Threat Intelligence team, Ransomware attacks have increased by 41 per cent in Asia, as resurgent threat actor groups seized the lead in November. The number of ransomware attacks in November increased by 41 per cent, from 188 to 265 occurrences, making it the busiest month since April of this year.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Threat actors Royal and Cuba, who are responsible for 16 per̥ cent and 15 per cent of all attacks, have displaced Lock bit 3.0 as the top threat actor. However, Lock bit 3.0 is still in use, coming in third and accounting for 12 per cent of attacks this month.
In contrast to the typical ransomware-as-a-service architecture the group typically observes, Royal, which NCC first monitored in January 2022, involves numerous skilled ransomware attackers operating independently. Cuba has been active over the past two years, although activity has decreased even though it was behind several high-profile attacks and demanded over USD 60 million in ransom.
The Cuban operation surprised everyone by carrying out a record 40 attacks in November, while typically keeping a low profile. Even though Lock bit 3.0 has continued to rank among the top three threat actors this month, the number of reported attacks is much lower than what was anticipated for the group.
DDoS attacks are increasing, with 3,648 attacks recorded in November, the same number as in October. With 1,543 attacks or 42 per cent of all detected DDoS attacks for the month, the United States continued to be the country that was attacked the most globally.
The enormous attack surface and ongoing geopolitical tensions in the nation, which show no signs of abating, are two factors contributing to the United States being the most targeted.
Furthermore, given the time of the US strikes, one explanation would be a desire to sabotage the midterm elections. The most frequently targeted region overall was North America, which saw 151 ransomware attacks (45 per cent) vs Europe's 65 (25 per cent).
With 14 per cent of attacks, Asia remained the third most often targeted region. In terms of sector trends, consumer cyclical (44 per cent) and industrials (32 per cent) continue to be the top two industries most frequently the target of ransomware attacks.
The NCC has noticed a significant 75 per cent increase in technology over the past month, with supply chain compromising potential and intellectual property still being the top targets. Royal and Cuba returned to the top two positions, pushing Lock bit 3.0 down to third. They will closely monitor any developments in this sector, but the diminished activities may indicate that the group is disbanding.
More in News