Lockbit Reigns Supreme as Global Ransomware Attacks Surge Following Conti Restructuring

The global cybersecurity landscape experienced a sharp and troubling escalation in malicious cyber activity during the mid-summer months, driven primarily by the relentless expansion of the Lockbit syndicate and the resurgence of splintered factions originating from the disbanded Conti operation. According to comprehensive threat intelligence data published by the NCC Group, successful ransomware campaigns surged by 47 percent in July, reversing a brief springtime dip and once again placing public sector entities, critical infrastructure, and private corporations on high alert.
Researchers utilizing active monitoring protocols across underground leak sites documented 198 successful ransomware attacks in July, a notable increase from the 135 incidents recorded in June. Although this figure remains safely below the staggering peaks observed earlier in the spring—when both March and April recorded nearly 300 successful campaigns each—the velocity of the rebound has alarmed cybersecurity professionals worldwide. The driving force behind this mid-summer surge is a combination of established ransomware-as-a-service (RaaS) powerhouses and rapidly adapting criminal groups that have successfully reorganized in the wake of international law enforcement pressure.
Lockbit, operating primarily through its advanced and highly structured Lockbit 3.0 framework, solidified its position as the undisputed leader of the global ransomware ecosystem. During July alone, the group was attributed to 62 successful attacks. This figure represents a ten-incident increase over its June performance and eclipses the combined totals of its closest competitors by more than two to one. Threat intelligence analysts have repeatedly emphasized that Lockbit’s operational maturity, reliable affiliate network, and persistent innovation make it one of the most formidable threats facing modern enterprises.
The Conti Diaspora: Rise of the Splinter Factions
While Lockbit maintained its dominant market share, the broader movement within the threat landscape was defined by the aggressive rise of groups tied directly to the legacy of Conti. Earlier in the year, Conti reigned as the undisputed heavyweight of the global ransomware ecosystem, operating with virtual impunity from safe havens and extorting hundreds of millions of dollars from high-profile victims. However, intense geopolitical friction, public exposure of internal communications following the onset of the Russia-Ukraine conflict, and aggressive counter-offensive measures by Western governments ultimately fractured the syndicate.
In May, the United States Department of State escalated its campaign against the Russian-based cybercrime organization by issuing a reward of up to $15 million for information leading to the identification or location of key Conti leadership figures. This unprecedented financial bounty, combined with targeted sanctions and coordinated law enforcement disruptions, effectively forced the sprawling criminal enterprise to dissolve its centralized command structure.
Rather than vanishing from the threat landscape, however, the operatives behind Conti simply dispersed. Threat intelligence researchers tracking underground forums and analyzing cryptographic strains observed that the core infrastructure split into distinct factions, affiliates, and derivative strains. By July, these successor elements had successfully transitioned out of their structural reorganization phase and re-entered the operational arena with devastating efficiency.
Among the most prominent beneficiaries of this diaspora are Hiveleaks and BlackBasta, both of which registered explosive growth trajectories in July. Hiveleaks surged by an astounding 440 percent, launching 27 verified attacks compared to a nominal footprint just a month prior. Meanwhile, BlackBasta—widely assessed by cybersecurity analysts to be a direct structural or operational successor utilizing codebases and methodologies reminiscent of Conti—recorded 24 attacks, representing a 50 percent month-over-month increase. Combined, these two groups accounted for 51 successful extortion events in July, effectively filling the vacuum left by the original Conti monolithic brand.
Chronology of the 2022 Ransomware Resurgence
To understand the current trajectory of cyber extortion, it is necessary to examine the cascading events that shaped the threat ecosystem over the first seven months of 2022:
- January – February 2022: The year commenced with a steady cadence of ransomware incidents, averaging roughly 250 to 270 attacks per month. Major syndicates such as Conti, Lockbit, and BlackCat maintained high operational tempos, targeting manufacturing, healthcare, and technology sectors.
- Late February 2022: Following the geopolitical escalation in Eastern Europe, internal dissension within Conti led to a massive leak of internal chat logs, source code, and cryptocurrency wallet addresses by a disgruntled affiliate. This breach exposed the inner workings, hierarchy, and operational infrastructure of the syndicate.
- March – April 2022: Ransomware activity reached its annual apex, with campaigns touching nearly 300 victims per month in both March and April. Groups rushed to monetize existing vulnerabilities and exploit lingering network exposures before international law enforcement could mobilize coordinated interventions.
- May 2022: The United States Department of State formally announced a multi-million-dollar reward program targeting Conti leadership. Concurrently, European law enforcement agencies stepped up infrastructure seizures and asset freezes. Under severe pressure, Conti leadership formally initiated the dismantling of the unified brand, directing members to operate in smaller, decentralized cells.
- June 2022: The ransomware ecosystem experienced a temporary lull. Successful campaigns dropped to 135 globally as former Conti operatives paused offensive operations to establish new communication channels, launder accumulated cryptocurrency, and rebrand their infrastructure under names such as BlackBasta and Hiveleaks.
- July 2022: The post-reorganization phase concluded. Ransomware attacks rebounded sharply by 47 percent to 198 incidents. Lockbit reinforced its market dominance with 62 attacks, while Hiveleaks and BlackBasta emerged as primary growth vectors, signaling that the decentralized remnants of Conti had fully adapted to the new enforcement environment.
Quantitative Analysis of the July Threat Landscape
The empirical data compiled by the NCC Group underscores a shifting paradigm in how cybercriminal organizations scale their operations. The reliance on RaaS models—wherein core developers lease their malicious infrastructure and encryption tools to affiliate hackers in exchange for a percentage of the ransom—continues to lower the technical barrier to entry while maximizing the frequency of attacks.
Lockbit’s 62 attributed attacks in July represent approximately 31 percent of all global ransomware incidents tracked during the period. This concentration of power highlights the platform’s resilience against routine disruption efforts. Furthermore, the rapid scaling of Hiveleaks (27 attacks) and BlackBasta (24 attacks) demonstrates that brand fragmentation does not equate to a loss of offensive capability. Instead, decentralization has introduced a competitive market dynamic among cybercriminal factions, inadvertently driving up the total volume of attacks as each splinter group strives to prove its viability to prospective affiliates and initial access brokers.
Geographically and sectorally, the targets of these campaigns remain broadly distributed. Manufacturing, professional services, technology, and healthcare organizations continue to bear the brunt of the extortion attempts. Threat actors increasingly leverage multi-layered extortion tactics—combining data encryption, public leak site shaming, direct intimidation of corporate clients, and distributed denial-of-service (DDoS) attacks—to compel victim organizations into meeting ransom demands.
Implications for Corporate Security and Defense Strategies
The resurgence of ransomware, characterized by the hyper-prolific output of Lockbit and the phoenix-like rebirth of Conti elements, carries profound implications for Chief Information Security Officers (CISOs) and corporate risk management committees.
First, the data demonstrates that traditional law enforcement disruptions, while critical for destabilizing major syndicates, often produce unintended secondary effects in the short term. The dissolution of a monolithic threat group like Conti does not eradicate the underlying human capital or technical expertise; rather, it disperses skilled threat actors into smaller, harder-to-track cells that quickly proliferate across the threat landscape. Organizations must therefore maintain continuous vigilance rather than assuming that the public takedown or voluntary disbandment of a specific ransomware brand signals a reduction in systemic risk.
Second, the dominance of RaaS models necessitates a fundamental shift in defensive postures. Protecting an enterprise perimeter is no longer sufficient when ransomware affiliates specialize in purchasing stolen valid credentials from initial access brokers or exploiting unpatched edge-device vulnerabilities. Security teams must adopt comprehensive zero-trust architectures, enforce rigorous multi-factor authentication (MFA) across all administrative and remote access portals, maintain immutable and segmented offline backups, and implement continuous behavioral monitoring to detect lateral movement before payload deployment occurs.
As the cybersecurity community moves deeper into the second half of the year, threat intelligence analysts warn that the current upward trajectory in attack volume is likely to persist. With Lockbit continuing to innovate its platform features—exemplified by the ongoing rollout and refinement of Lockbit 3.0—and Conti’s successor groups fully settled into their new operational paradigms, organizations across all industry verticals must treat threat intelligence not as a passive reporting mechanism, but as an active component of their strategic defense planning.







