ZeroFox Intelligence Brief - Ransomware Threat Landscape Continues to Diversify in 2024
|by Alpha Team

ZeroFox Intelligence Brief - Ransomware Threat Landscape Continues to Diversify in 2024
Product Serial: B-2024-04-23a
TLP:CLEAR
In this Brief Report, ZeroFox researchers report on the increasing diversification of threat collectives conducting ransomware and digital extortion attacks, as well as the reduction of ALPHV and LockBit activity.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- The frequency of ransomware and digital extortion (R&DE) attacks is on an upward trajectory, with the number of observed incidents during Q1 2024 only slightly less than that of the previous quarter, despite Q4 2023 constituting more attacks than any other quarter observed by ZeroFox.
- So far in 2024, the five most active collectives have been responsible for a continually-decreasing proportion of total R&DE activity. This is indicative of a growing number of highly-active threat groups, many of which are exhibiting an upward trajectory in their attack frequency.
- Several smaller threat groups, such as DarkVault, DragonForce, MyData, and Red, have displayed high attack tempos, which are historically atypical for newer collectives. It is very likely that such groups are benefitting from the acquisition of experienced affiliates from LockBit and ALPHV.
- It is likely that the R&DE threat landscape will continue to diversify during the coming months, with an increasing number of threat collectives conducting a growing proportion of total activity.
Tags: tlp:clear, threat actor, DDW Ransomware