Cyber Affairs
No Result
View All Result
  • Login
  • Register
  • Home
  • Live Threat Map
  • Books
  • Careers
  • Latest
  • Podcast
  • Popular
  • Press Release
  • Reports
  • Tech Indexes
  • White Papers
  • Contact
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
COMMUNITY
NEWSLETTER
  • AI
  • Cyber Crime
  • Intelligence
  • Laws & Regulations
  • Cyber Warfare
  • Hacktivism
  • More
    • Digital Influence Mercenaries
    • Digital Diplomacy
    • Electronic Warfare
    • Emerging Technologies
    • ICS-SCADA
    • Books
    • Careers
    • Cyber Crime
    • Cyber Intelligence
    • Cyber Laws & Regulations
    • Cyber Warfare
    • Digital Diplomacy
    • Digital Influence Mercenaries
    • Electronic Warfare
    • Emerging Technologies
    • Hacktivism
    • ICS-SCADA
    • News
    • Podcast
    • Reports
    • Tech Indexes
    • White Papers
NEWSLETTER
No Result
View All Result
Cyber Affairs
No Result
View All Result
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers
Home Cyber Intelligence

Royal overtakes LockBit as top ransomware in November as attacks increase 41%

admin by admin
Dec 21, 2022
in Cyber Intelligence
0 0
A A
0
FacebookTwitterLinkedIn
LockBit ransomware fell two spots to No. 3 in November as Royal and Cuba ransomware claimed the top two spots, respectively, according to new research from the NCC Group.

Ransomware attacks rose 41% last month as threat actor groups shifted top spots, according to new research from NCC Group.  

November’s sharp increase in reported incidents is backed by uncommon contributions. According to the research, threat groups Royal and Cuba claimed first and second place as most active and accounted for 16% and 15% of all attacks, knocking LockBit from the top spot for the first time since September 2021.  

“Although LockBit appears to have sloped off this month in terms of total organizations compromised, it is possible that the newcomers to the top three threat actors are amassing as many victims as they can before the holidays, in preparation for 2023,” NCC Group warned in the report.  

Royal ransomware — a strain that emerged in January — works without affiliates and is therefore different from the traditional ransomware-as-a-service model. The strain targets Windows systems with a 64-bit executable written in C++ while files are encrypted with the AES standard and appended with the .royal extension, NCC Group said.  

“Royal has a more human touch than traditional ransomware attackers like LockBit,” said Matthew Fulmer, manager of cyber intelligence engineering at Deep Instinct. “They use social engineering as their delivery mechanism, and they will reach out under the guise of callback phishing attacks.”  

Indeed, threat actors delivering Royal ransomware have been observed to use innovative methods to obfuscate the payload. In November, Microsoft reported that a threat actor tracked as DEV-0569 embedded phishing links in contact forms on target companies’ websites. According to Microsoft, the group also hosts fake installer files on legitimate-looking software download sites to make malicious downloads look authentic while using Google Ads to expand their malvertising technique further.  

Microsoft also recognized DEV-0569 as access brokers for ransomware operations — this, alongside concerns that additional ransomware groups are also using Royal strain, may explain the recent sharp increase in Royal ransomware, NCC Group said.  

Besides the insurgence of the new group, the report highlighted that the relatively old Cuba ransomware group has made an “alarming” and “uncharacteristic” contribution with its largest number of attacks recorded by the NCC Group in nearly two years.  

 
 Cuba ransomware attacks 2021 vs 2022 (credit: NCC Group)  
 

“Looking back over the last two years, the number of Cuba ransomware attacks had been noticeably quiet,” the report read. “As such, a record number of 40 attacks in November is highly unexpected from the Cuba operation. Whether this is the start of a more active Cuba operation and one which moves the variant to the top three ranking on a more permanent basis will remain to be seen.”  

“We certainly anticipate spikes and fluctuations in threat actor behaviors, however, the significant jump observed here may signal a more frequent, higher level of targeting,” NCC Group added.  

Though LockBit 3.0 remained active, taking third place, and making up 12% of attacks last month, NCC Group said its attacks were “substantially less” than expected.  

Matt Hull, global head of threat intelligence at NCC Group, said in a statement that the reduced operation in LockBit 3.0 may suggest the group could be disbanding. Fulmer, however, warned that organizations should not drop their guards.  

“LockBit lost a bit due to their builder being leaked [in September this year] and some of the internal information about their encryptor becoming public. This just means they will regroup and rebuild to come back stronger with more resilience and tighter internal protections,” Fulmer said.  

“[LockBit] will likely continue to be one of the most prolific ransomware strains observed in 2023,” Brad Crompton, intelligence director at Intel 471, added. 

Read the full article here

ShareTweetSharePinShareShareSend

Related Articles

Cyberattack on Fintech Firm Disrupts Derivatives Trading Globally
Cyber Intelligence

Cyberattack on Fintech Firm Disrupts Derivatives Trading Globally

Palo Alto Networks and TELMEX-Scitum Reinforce Their Commitment to Offer Extended Managed Detection and Response (XMDR)
Cyber Intelligence

Palo Alto Networks and TELMEX-Scitum Reinforce Their Commitment to Offer Extended Managed Detection and Response (XMDR)

Using real-time data platforms to plug cybersecurity skills gap
Cyber Intelligence

Using real-time data platforms to plug cybersecurity skills gap

Trace3, ExtraHop Launch Managed Detection and Response (MDR) Services
Cyber Intelligence

Trace3, ExtraHop Launch Managed Detection and Response (MDR) Services

Spain: Rights experts call for probe into claim Catalan leaders were spied on
Cyber Intelligence

Spain: Rights experts call for probe into claim Catalan leaders were spied on

Enterprise Exposure to Cyberattacks Vastly Elevated with Increased Dependency on Third-Party Partners
Cyber Intelligence

Enterprise Exposure to Cyberattacks Vastly Elevated with Increased Dependency on Third-Party Partners

How Do Threat Hunters Keep Organizations Safe?
Cyber Intelligence

How Do Threat Hunters Keep Organizations Safe?

Cyber Threat Intelligence Services Market to Witness Huge
Cyber Intelligence

Cyber Threat Intelligence Services Market to Witness Huge

APT groups use ransomware TTPs as cover for intelligence gathering and sabotage
Cyber Intelligence

APT groups use ransomware TTPs as cover for intelligence gathering and sabotage

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended Stories

Hackers Actively Using Pupy RAT to Attack Linux Systems

Hackers Actively Using Pupy RAT to Attack Linux Systems

Buckle Up_ BEC and VEC Attacks Target Automotive Industry

Buckle Up_ BEC and VEC Attacks Target Automotive Industry

Chinese Chipmaker Nexperia: Gigabytes of Data Stolen

Chinese Chipmaker Nexperia: Gigabytes of Data Stolen

Popular VPN Software Flaw Let Attackers Crash the Systems

Popular VPN Software Flaw Let Attackers Crash the Systems

Hackers Customize LockBit 3.0 Ransomware To Attack Orgs Worldwide

Hackers Customize LockBit 3.0 Ransomware To Attack Orgs Worldwide

The most important cyber news and events of the day

Be the first to know latest important news & events directly to your inbox.

By signing up, I agree to our TOS and Privacy Policy.

Popular Stories

  • Fortinet Vulnerability Exploited To Deploy RMM Tools & Backdoor

    Fortinet Vulnerability Exploited To Deploy RMM Tools & Backdoor

    0 shares
    Share 0 Tweet 0
  • Malware Trends 2024 – Top Malware Families and Types

    0 shares
    Share 0 Tweet 0
  • French Football Club Ticketing System Targeted in Cyber Attack

    0 shares
    Share 0 Tweet 0
  • Argentina – Global Investigations Review

    0 shares
    Share 0 Tweet 0
  • Singha Durbar server continues to face cyberattacks

    0 shares
    Share 0 Tweet 0
Cyber Affairs

Cyber Affairs is your one-stop news website for the latest cyber crime, cyber warfare, and all cyber related news and updates, follow us to get the news that matters to you.

LEARN MORE »

Recent News

  • Hackers Actively Using Pupy RAT to Attack Linux Systems
  • Buckle Up_ BEC and VEC Attacks Target Automotive Industry
  • Chinese Chipmaker Nexperia: Gigabytes of Data Stolen

Topics

  • AI
  • Books
  • Careers
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • News
  • Podcast
  • Reports
  • Tech Indexes
  • Uncategorized
  • White Papers

Get Informed

The most important cyber news and events of the day

Be the first to know latest important news & events directly to your inbox.

By signing up, I agree to our TOS and Privacy Policy.

Copyright © 2022 Cyber Affairs. All rights reserved.

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Intelligence
  • Cyber Laws & Regulations
  • Cyber Warfare
  • Digital Diplomacy
  • Digital Influence Mercenaries
  • Electronic Warfare
  • Emerging Technologies
  • Hacktivism
  • ICS-SCADA
  • Reports
  • White Papers

Copyright © 2022 Cyber Affairs. All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.