ZeroFox Intelligence Flash Report - Ransomware and Digital Extortion Landscape Diversifying
|by Alpha Team

ZeroFox Intelligence Flash Report - Ransomware and Digital Extortion Landscape Diversifying
Product Serial: F-2023-11-09a
TLP:CLEAR
In this Intelligence Flash Report, ZeroFox researchers report on the diversifying ransomware and digital extortion threat landscape, with a fall in the operational tempo of attacks by major strains, and new threat collectives demonstrating proficiency at pace.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- The operational tempo of ransomware and digital extortion (R&DE) collectives LockBit and ALPHV is steadily decreasing, both in the number of observed incidents and as a proportion of all R&DE activity.
- Since at least Q2 2023, several newly-observed R&DE threat collectives have conducted increasingly frequent attacks. Some of these are likely rebrands of established threat collectives and others former affiliates of LockBit and ALPHV launching their own operations.
- New threat collectives are demonstrating proficiency at a faster pace than previously observed and are more than offsetting the decline in LockBit and ALPHV activity. This will likely drive significant change across the R&DE threat landscape in coming quarters.
Tags: tlp:clear, dark web, all industries, DDW Ransomware