No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Fresh Ransomware Gangs Emerge As Market Leaders Decline

June 20, 2023
in Protection
0
Fresh Ransomware Gangs Emerge As Market Leaders Decline



There was a rise in the number of ransomware victims in May compared to the previous month, although LockBit, the leading ransomware group, saw a 30% decrease in observed victims (110 to 77) from April to May.

Ransomware heavyweight AlphV also experienced a decline in posted victims, with 38 observed victims in May compared to 51 in April.

That drying up was offset by several new branded groups entering the scene, contributing to an overall increase in observed ransomware victims, according to GuidePoint Security’s latest GRIT report.

The May GRIT report highlighted a diverse slate of active threat groups, with 28 observed groups claiming victims. There was a 13.57% increase in publicly posted ransomware victims from April to May, and 410 incidents total, led by victims in the United States — far and away the most targeted country.

The report noted that the fledgling Akira ransomware group has gained particular prominence just since April (the name a potential nod to the 1988 Japanese anime cult classic in which a biker is turned into a rampaging psychopath). The gang is primarily known for a unique data-leak site designed as an interactive command prompt using jQuery.

Educational organizations have been disproportionately targeted by Akira, representing eight of its 36 observed victims. The group follows the “double extortion” approach: stealing data from victims and threatening to leak it if the ransom is not paid.

While there isn’t enough data to make a definitive hypothesis, GuidePoint Security threat intelligence consultant Nic Finn notes he has observed some of the new groups significantly lowering their initial ransomware demand.

“If this trend continues, it could indicate that ransomware groups are attempting to shorten the time between victimization and ransomware payment,” he says.

Overall, though, the GRIT findings echoed the 2023 Verizon Data Breach Investigations Report in noting escalating ransomware costs.

Emergence of New Ransomware Groups

GRIT has also identified other fresh-faced ransomware groups on the scene, such as 8Base, Malas, Rancoz, and BlackSuit, each with its own distinct characteristics and targets.

8Base, which claimed 67 victims in the past year, has primarily targeted the banking and finance industry and is focused primarily on the US and Brazil, while the extortion group Malas was observed performing mass exploitation of business email and collaboration software Zimbra.

There is little known about Rancoz, which has posted just two victims so far — one in the tech sector and one in manufacturing — while BlackSuit was flagged for the maturity of its operations despite only one observed victim.

These emerging threat groups have deployed a combination of established and innovative tactics, aiming to blend in and profit amid the crowded ransomware landscape, explains Finn.

He notes one method that’s been observed lately is a shift toward single extortion, focused around exfiltrated data — no encryption necessary.

“This is much more sustainable for ransomware groups because it involves less troubleshooting with victims when the decryptors fail,” he says.

Finn explains the recent behavior of ransomware groups suggests they are following whatever tactics they believe to be more novel and successful.

“The trend back toward single extortion through the threat of data publication could be the result of perceived success by other groups, or it could be a determination they are making based on their interactions with victims,” he says.

For example, if a good portion of their victims are asking to lower the ransom demand in exchange for just proof of deletion and guarantees not to attack them again, this may lead ransomware groups to assume that a good portion of their victims have backups in place, making it the effort of encrypting a victim network seem superfluous.

“Organizations following data backup best practices should remain diligent about developing detections and monitoring activity for any potential data exfiltration efforts, as this single extortion trend will definitely continue and likely grow throughout 2023,” Finn says.

Education Sector in the Sights

As evidenced by Akira and older groups like Vice Society, ransomware groups are increasingly targeting educational institutions, from daycare centers to major universities. In total, ransomware groups posted 35 unique victims in the education industry in May.

“A recent influx in vulnerabilities affecting software commonly used in schools, such as the PaperCut MF/NG vulnerability,” the report noted.

“It seems like the education sector is seeing heavy targeting because there is so much personally identifiable (PII) and sensitive student data available in the resulting data,” Finn says. “Additionally, the number of individuals impacted is exponential to the size of the victim organization.”

For example, a school system with just a thousand or so active students could still house records and data on thousands more former students, plus information relating to parents of the students who have data at risk.

“Another big factor is media attention,” he adds. “Ransomware actors follow the trends that get them media coverage. The cyberattack against the LA Unified School District brought about a lot of media attention, so it’s likely that more groups are matching that trend to replicate the coverage.”

MOVEit and Mass Exploitation

Another factor in the recent growth of successful ransomware attacks is the phenomenon of ransomware groups are exploiting zero-day vulnerabilities en masse, the report noted, conducting exfiltration, and expecting victims to reach out to them to coordinate for ransoms.

The ongoing Cl0p attacks exploiting the MOVEit vulnerability against hundreds of organizations are emblematic of the trend, which is also seen with the DeadBolt ransomware variant and another recently exploited by a threat actor to deploy Nokoyawa ransomware.

“It appears that Cl0p has a team of highly technical hackers working on mass exploitation, especially of file transfer software,” Finn adds.

Recent reporting indicates that the group began working on the MOVEit exploitation as far back as 2021, and even delayed the mass exploitation of the vulnerability until it completed a different mass exploitation campaign against the GoAnywhere MFT service earlier this year.

“This indicates a significant strategic planning capability, even down to the decision to begin exploitation of this MOVEit vulnerability over the Memorial Day weekend, when less staff is available to respond right away,” he says.

While there has been a noted slowdown in ransomware activity over the summer for the past two years, which Finn adds may still occur this year, there’s also “a good chance” that other ransomware groups attempt to mimic the behavior of groups like Cl0p and attempt mass exploitation, which could offset declines in activity elsewhere.

Editorial Team

Editorial Team

Related Posts

5 Hacks Every Nike Run Club User Should Know
Protection

5 Hacks Every Nike Run Club User Should Know

April 22, 2026
I Keep This Solis Pocket Wifi in a Travel Bag, and You Should Too
Protection

I Keep This Solis Pocket Wifi in a Travel Bag, and You Should Too

April 22, 2026
This Samsung Galaxy S26 Is $100 Off Right Now
Protection

This Samsung Galaxy S26 Is $100 Off Right Now

April 22, 2026
Galaxy Enhance-X Is Samsung's Best Photo and Video Editing Tool
Protection

Galaxy Enhance-X Is Samsung’s Best Photo and Video Editing Tool

April 22, 2026
The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘A Knight of the Seven Kingdoms'
Protection

The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘A Knight of the Seven Kingdoms’

April 22, 2026
How to Spot AI Audiobooks on Libby
Protection

How to Spot AI Audiobooks on Libby

April 21, 2026
Load More
Next Post
Hunt calls in banks for talks over spiralling UK mortgage costs

Hunt calls in banks for talks over spiralling UK mortgage costs

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Chainalysis: Crypto Money Laundering Surged to $82 Billion in 2025

    0 shares
    Share 0 Tweet 0
  • Strait of Hormuz tensions keep WTI crude oil market on edge as April deadline nears

    0 shares
    Share 0 Tweet 0
  • Among Michael Burry Stocks with Huge Upside Potential

    0 shares
    Share 0 Tweet 0
  • Contrary To Popular Belief, This Is Not The Worst Bitcoin Crash In History – Here’s The List

    0 shares
    Share 0 Tweet 0

Latest News

5 Hacks Every Nike Run Club User Should Know

5 Hacks Every Nike Run Club User Should Know

April 22, 2026
0

We may earn a commission from links on this page. The Nike Run Club app is a longtime favorite for...

Ethereum

Ethereum Staking Hits Fresh High As Network Locks Up More ETH

April 22, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ethereum staking activity continues to experience sharp...

Hoka Promo Codes and Deals: Up to 30% Off in April

Hoka Promo Codes and Deals: Up to 30% Off in April

April 22, 2026
0

To distract myself on long runs, I often look at the shoes and clothes of other runners around me. More...

Lazarus Group Malware Targets Crypto, Business Execs via macOS

Lazarus Group Malware Targets Crypto, Business Execs via macOS

April 22, 2026
0

Security researchers have linked a new macOS malware campaign to the Lazarus Group, the North Korea-linked hacking operation behind some...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.