LockBit Dominates Summer Ransomware Landscape Amidst Resurgence Driven by Conti Offshoots

Following a noticeable dip in activity, ransomware attacks have re-emerged with a vengeance this summer, largely propelled by established ransomware-as-a-service (RaaS) operations. Data compiled by NCC Group’s Monthly Threat Pulse for July 2022 reveals a significant uptick in compromises, with the LockBit group exhibiting unparalleled prolificacy. This surge also highlights the persistent influence of Conti, a notorious ransomware syndicate that, despite apparent restructuring, continues to cast a long shadow over the cyber threat landscape through its successor entities.
NCC Group’s researchers meticulously monitored the leak sites utilized by various ransomware groups, systematically scraping victim details as they were disclosed. This rigorous data collection process identified LockBit as the most active ransomware gang in July, responsible for an estimated 62 attacks. This figure represents a notable increase from the preceding month and surpasses the combined total of the second and third most prolific groups by a considerable margin. The report explicitly states, "LockBit 3.0 maintains their foothold as the most threatening ransomware group, and one with which all organizations should aim to be aware of." The group’s sustained dominance underscores its operational resilience and its continued ability to exploit vulnerabilities across a wide array of sectors.
Trailing LockBit in terms of reported attacks were Hiveleaks and BlackBasta, attributing 27 and 24 attacks respectively. These figures are particularly striking given the rapid escalation of activity for both groups. Hiveleaks, in particular, witnessed an astonishing 440 percent surge in its attack count since June, while BlackBasta saw a still-substantial 50 percent increase over the same period. This concurrent rise of these two groups, coupled with the overall resurgence in ransomware incidents, suggests a potentially intimate connection between the restructuring of established criminal enterprises and the current threat environment.
Ransomware Attacks Rebound: A July Overview
The data from NCC Group paints a clear picture of a renewed offensive by ransomware actors. In July, researchers documented a total of 198 successful ransomware campaigns, marking a significant 47 percent increase compared to June. While this upward trajectory is substantial, it still falls short of the peak activity observed earlier in the spring, when both March and April saw nearly 300 ransomware campaigns each. This suggests that the current resurgence, while concerning, may not yet have reached its zenith.
The cyclical nature of ransomware attacks often reflects shifts in operational strategies, law enforcement interventions, and the evolving dynamics within cybercriminal syndicates. The recent uptick is widely believed to be intrinsically linked to the fragmentation and subsequent re-emergence of the Conti ransomware group.
The Conti Conundrum: A Catalyst for Resurgence?
The significant pressure exerted by international law enforcement and cybersecurity agencies on major ransomware operations, including Conti, appears to have inadvertently reshaped the threat landscape. In May 2022, the United States government intensified its efforts against Russian-linked cybercrime by offering substantial rewards, up to $15 million, for information leading to the apprehension of individuals associated with the Conti ransomware variant. At that time, Conti was considered the preeminent ransomware gang globally.
The authors of the NCC Group report speculate that this increased pressure likely prompted "threat actors that were undergoing structural changes… and have begun settling into their new modes of operating, resulting in their total compromises increasing in conjunction." This period of disruption and reorganization within prominent groups, particularly Conti, appears to have led to a redistribution of resources and expertise.
Hiveleaks and BlackBasta: The Conti Legacy
The emergence and rapid ascent of Hiveleaks and BlackBasta are directly linked to this internal restructuring within Conti. Both groups are described as being "associated with Conti." Hiveleaks is identified as an affiliate that likely branched off or adopted a new identity, while BlackBasta is characterized as a "replacement strain." This indicates a strategic evolution where the core infrastructure, methodologies, or even personnel from Conti have been repurposed and rebranded. The report notes, "As such, it appears that it has not taken long for Conti’s presence to filter back into the threat landscape, albeit under a new identity."
This phenomenon of rebranding and splintering is a common tactic employed by ransomware groups to evade detection and prosecution, maintain operational continuity, and potentially circumvent internal disputes or law enforcement actions. The Conti group, once a monolithic entity, has seemingly undergone a fission, with its constituent parts now operating under new banners, yet retaining a discernible operational lineage.
Implications and Future Outlook
The implications of this trend are multifaceted and concerning for organizations worldwide. The re-emergence of sophisticated ransomware operations, driven by experienced actors, means that businesses face a heightened risk of disruption, data exfiltration, and significant financial losses. The increased activity of LockBit, coupled with the burgeoning influence of Conti’s offshoots, signals a more aggressive and fragmented threat environment.
The fact that these groups are operating under RaaS models further democratizes access to sophisticated cyberattack tools, enabling less technically adept individuals to launch complex operations. This lowers the barrier to entry for aspiring cybercriminals, potentially leading to an even greater volume of attacks in the future.
The ongoing battle against ransomware requires a multi-pronged approach. While law enforcement efforts to dismantle criminal infrastructure and apprehend individuals are crucial, they must be complemented by robust cybersecurity measures at the organizational level. This includes implementing strong security protocols, conducting regular vulnerability assessments, providing employee training on cyber hygiene, and developing comprehensive incident response plans.
The NCC Group’s analysis suggests that the current trend is likely to continue. The report’s authors further speculate, "Now that Conti’s properly split in two, it would not be surprising to see these figures further increase as we move into August." This forecast underscores the urgency for organizations to remain vigilant and proactive in their defense against evolving cyber threats.
Broader Context: The Evolution of Ransomware
Ransomware has evolved from a niche cybercrime to a global security crisis. Initially characterized by relatively simple encryption and extortion tactics, it has transformed into a highly sophisticated criminal enterprise. Modern ransomware operations often involve double or triple extortion, where victims not only face data encryption but also the threat of data leaks and distributed denial-of-service (DDoS) attacks if they refuse to pay.
The RaaS model has been a key enabler of this evolution. Under this model, developers of ransomware lease their malicious software to affiliates who then conduct the actual attacks. The developers take a cut of the ransom payments, while affiliates pocket the majority. This division of labor allows for specialization and scalability, making ransomware operations more efficient and profitable.
Conti, before its apparent fragmentation, was a prime example of a highly organized and successful RaaS operation. Its affiliates were responsible for a significant number of high-profile attacks targeting critical infrastructure, government entities, and large corporations. The group’s tactics, techniques, and procedures (TTPs) were widely studied and emulated by other threat actors.
The recent shift in focus by law enforcement, particularly the substantial rewards offered for information on Conti, represents a strategic effort to disrupt the financial and operational backbone of these syndicates. While such actions can lead to temporary setbacks or restructuring, they also have the unintended consequence of dispersing criminal expertise and potentially creating new, albeit smaller, threat actors.
Key Takeaways for Organizations
The resurgence of ransomware, spearheaded by LockBit and Conti’s successor groups, serves as a stark reminder that the threat is far from diminished. Organizations must adopt a proactive and layered security posture. This includes:
- Robust Technical Defenses: Implementing strong endpoint protection, network segmentation, regular patching, and multi-factor authentication are fundamental.
- Data Backups and Recovery: Maintaining secure, offline, and regularly tested backups is critical for recovery in the event of an encryption attack.
- Incident Response Planning: Developing and practicing a comprehensive incident response plan ensures a swift and effective reaction to a cyberattack, minimizing damage and downtime.
- Threat Intelligence: Staying informed about the latest ransomware trends, threat actors, and their TTPs allows for better anticipation and mitigation of risks.
- Employee Awareness Training: Educating employees about phishing, social engineering, and safe computing practices is a crucial line of defense, as human error remains a significant attack vector.
- Collaboration and Information Sharing: Engaging with industry peers, cybersecurity firms, and law enforcement agencies to share threat intelligence and best practices can significantly enhance collective defense.
The summer of 2022 has demonstrated that ransomware remains a potent and adaptable threat. The ongoing evolution of groups like LockBit and the indirect influence of Conti’s legacy through Hiveleaks and BlackBasta necessitate continuous vigilance and adaptation from cybersecurity professionals and organizations alike. The battle against ransomware is an ongoing one, requiring sustained effort and strategic foresight to stay ahead of evolving criminal methodologies.







