We're excited to unveil the next chapter of Bitdefender Threat Debrief. Since 2021, we've been keeping the cybersecurity community informed about the evolving threat landscape through monthly reports on ransomware, phishing, honeypots, and Android trojans. This issue introduces a significant shift in data collection: ransomware reports will now leverage victim data directly from attacker websites. This replaces our prior reliance on detection data, offering a more comprehensive view of the threat landscape. Starting with this edition, we're bringing you the latest and newest ransomware news in each segment – it’s crucial intel every security expert should be on top of to stay ahead of threats.
This month reveals a disturbing tactic: new ransomware groups are attempting to poach disgruntled affiliates from groups like BlackCat (who recently pulled an exit scam). These affiliates, who may possess stolen data from previous attacks – data the victims already paid for – could be lured into a second extortion attempt, reopening old wounds for these companies. This gives a completely new meaning to “double-extortion”.
Staying ahead of ransomware attackers is a constant battle for security specialists. By monitoring trends in victim data, attack methods, and targeted industries, we can gain valuable insights into the evolving tactics of these cybercriminals.
The Threat Debrief leverages data directly from ransomware group websites, primarily focusing on their claimed victim counts. This approach offers valuable insights into the RaaS market's activity level by reflecting attackers' self-reported successes. However, it's crucial to acknowledge the inherent limitations. We are relying on information from criminals, and their claims may be inflated or fabricated. Additionally, this methodology only captures the number of claimed victims, not the actual ransom demands or payments made.
Now, let’s explore the most notable ransomware news and findings since our last Threat Debrief release:
Ransomware gangs prioritize targets where they can potentially squeeze the most money out of their victims. This often means focusing on developed countries. In March 2024, we analyzed data from ransomware group websites, identifying a total of 346 claimed victims. Now, let’s see the top 10 countries that took the biggest hit from these attacks.
The Bitdefender Threat Debrief (BDTD) is a monthly series analyzing threat news, trends, and research from the previous month. Don’t miss the next BDTD release, subscribe to the Business Insights blog, and follow us on Twitter. You can find all previous debriefs here.
Bitdefender provides cybersecurity solutions and advanced threat protection to hundreds of millions of endpoints worldwide. More than 180 technology brands have licensed and added Bitdefender technology to their product or service offerings. This vast OEM ecosystem complements telemetry data already collected from our business and consumer solutions. To give you some idea of the scale, Bitdefender Labs discover 400+ new threats each minute and validate 30 billion threat queries daily. This gives us one of the industry’s most extensive real-time views of the evolving threat landscape.
We would like to thank Bitdefenders Alin Damian, Mihai Leonte, Andrei Mogage, Silviu Sofronie, Rares Radu, Ioan Stan, Marius Tivadar, and Horia Zegheru (sorted alphabetically) for their help with putting this report together.
tags
Martin is technical solutions director at Bitdefender. He is a passionate blogger and speaker, focusing on enterprise IT for over two decades. He loves travel, lived in Europe, Middle East and now residing in Florida.
View all postsDon’t miss out on exclusive content and exciting announcements!