INFORME DE KELA

Ransomware Victims and Network Access Sales in Q1 2022

In Q1 2022, ransomware gangs maintained their status as a major threat.

Compartir:

KELA report cover: Ransomware Victims and Network Access Sales in Q1 2022

In Q1 2022, ransomware gangs maintained their status as a major and central threat. They collaborated with various cybercriminals, such as initial access brokers (IABs), and aimed to conduct attacks against corporations worldwide. The following insights are drawn from KELA’s monitoring of ransomware gangs and initial access brokers’ activity in Q1:The total number of ransomware victims (698) dropped by 40% in Q1 of 2022 compared to Q4 2021 (982), with LockBit replacing Conti as the most active gang since the beginning of the year. The number of attacks launched by the Conti gang dropped in January 2022 and increased following the leak of Conti’s internal data.•The finance sector made it to the top five targeted sectors with 46 attacks.40% of the attacks were associated with LockBit gang.•Ransomware gangs were seen using a relatively new intimidating method which includes publishing a victim without its name.•The number of network access listings on sale slightly increased compared to Q4 2021. KELA traced over 521 offers for sale with the cumulative price requested for all accesses surpassing $1.1 million, while in Q4 2021 KELAmonitored 468 access networks for sale.•The average sales cycle for network access is 1.75 days.KELA was able to identify more than 150 network access victims and then link some of them to ransomware attacks carried out by BlackByte, Quantum, and Alphv. The network accesses were most likely bought by ransomware affiliates.

Aspectos más destacados del informe:

  • 698 ransomware victims in Q1 2022, down 40% from Q4 2021, with LockBit replacing Conti as the most active gang
  • The Conti leak, the rise of Alphv, Hive and Karakurt, and the Lapsus$ arrests
  • The finance sector entering the top five targeted sectors with 46 attacks, 40% of them by LockBit
  • New intimidation methods: victims published without names by Midas, Lorenz and Everest, and fake leak sites such as LeakTheAnalyst and Stormous
  • Over 521 network access offers worth more than USD 1.1 million, a 1.75-day sales cycle, and 150+ victims linked to BlackByte, Quantum and Alphv attacks

Descargar el informe

Recursos relacionados

Banner del seminario web bajo demanda de KELA: Las detenciones de TeamPCP, desde dentro, con Ben Kapon y Jimmy

Las detenciones de TeamPCP, desde dentro

Portada del informe de KELA: Perfil del actor malicioso TeamPCP

Perfil del actor malicioso TeamPCP

Banner del comunicado de prensa de KELA: «Última hora: una investigación de KELA conduce a la detención de presuntos miembros de TeamPCP», en el que se ve a la policía escoltando a una persona detenida

Una investigación de KELA conduce a la detención de presuntos miembros de TeamPCP