Cybercriminals, naturally, go to great lengths to steal precious sensitive data.

One of their tried-and-true methods — and available at a modest price — is anti-detection browsers, commonly referred to as “antik.” Attackers can apply these tools to analyze, replicate and take advantage of digital behavior, all while evading detection.

According to the newest Cyber Threat Intelligence Report from NCC Group, such anti-detection methods are a strong contributor to a dramatic increase in ransomware activity.

Between October 2022 and 2023, ransomware attacks increased by 81%, according to NCC’s research. Furthermore, by the end of  October, ransomware gangs had already claimed over 50% more victims than in all of 2022.

“In the current turbulent climate, both economically and geopolitically, threat actors are looking for new ways to make money,” said Matt Hull, global head of threat intelligence at NCC Group. “As always, this highlights the need for organizations to continue taking robust cybersecurity measures to counteract these insidious practices.”

Good and bad ransomware news

While numerous ransomware groups and threat actors emerge all the time, incumbents still reign supreme. According to the NCC report, the ransomware-as-a-service (RaaS) group Lockbit 3.0 remained the most active cybercriminal group in October, with 19% (66) of total attacks, including a high-profile one on aircraft giant Boeing.

Following behind were ransomware gangs Akira, Medusa, INC Ranso, Play and NoEscape.

Still, October saw a 50% decrease in attacks on technology organizations and a 34% drop from a record monthly high in September.

However, Hull cautioned, “the decrease in attacks from September shouldn’t give us a false sense of security.”

There is often a reduction in attacks after a record month, he explained. NCC attributes October’s drop to a quieting activity from multi-extortion group LostTrust, which just emerged in September and was responsible for 10% of attacks that month.

There were also significant law enforcement takedowns of groups Trigona and RagnarLocker and the purported shutdown of RansomedVC.

Industrials, consumer cyclicals, healthcare most heavily hit Across industries, industrials still bear the brunt of attacks (accounting for 33% in October).

“The industrials sector is especially valuable for threat actors due to the wealth of personally identifiable information and intellectual (PII) property held by organizations within, many of which are large with expansive attack surfaces,” the NCC report states.

Within that industry, the three most targeted areas were professional and commercial services, construction and engineering and machinery, tools, heavy vehicles, trains and ships.

“Professional and commercial services companies will often hold vast troves of PII and commercially sensitive data, thus increasing the leverage an attacker has over a victim should they be able to encrypt/exfiltrate any data,” according to the report.

As such, industrial organizations must keep up to date with the latest tactics, techniques and procedures and “be conscious of the elevated threat of ransomware to the sector,” the report emphasizes.

Second to the industrial sector was consumer cyclicals — or stocks that cater to individuals and households. This is because client data such as addresses and payment details serve as “ready ammunition” for threat actors engaging in extortion, according to NCC.

Coming in third most targeted in October was healthcare. Although there has been some “noble rhetoric” of some cyberattackers avowing not to attack the sector, “other actors have shown no such moral or ethical qualms, and the healthcare sector continues to receive a steady stream of ransomware attacks,” the report asserts.

Further, America and Europe are — by wide margins — the first and second-most targeted regions around the globe.

Everyday life of a threat actor Beyond status, this month’s report delved into “the sentimentalities of the everyday life of a threat actor.”

“Do you ever think about the daily life of a threat actor? Most likely not,” the report posits. “But they certainly think about your daily life.”

As NCC explains, every website analyzes visitor data: who they are, where they’re from and their interests, among other information. All this is then aggregated into a user profile — which is highly coveted by threat actors.

To attempt to get ahold of that profile, attackers are increasingly leveraging antik, which conceals fingerprints, allowing them to create numerous unique browser profiles across multiple tabs without triggering anti-fraud systems. They have the ability to create, as NCC puts it, “a bushel of accounts” with different profiles, each assuming the identity of another device and profile. Thus, they can fly under the radar of websites that scrutinize visitor data.

“These tools, while also being used for legitimate means, provide opportunities for malicious actors and make it harder for defenders to track down, prevent and detect attacks,” said Hull.

The report calls these methods the “lifeblood of cybercrime, keeping the underground economy alive.” Antik is responsible for facilitating numerous compromises and “massive money drains.”

Furthermore, NCC researchers observe, “potentially it can pave the way for bigger and more spoken about cyber threats.”