United Kingdom-based cybersecurity vendor NCC Group found the LockBit ransomware gang usurped the Conti ransomware gang as the most prolific threat actor in 2022, with the former responsible for 33% of monitored ransomware attacks last year. The change comes amid ransomware groups facing increased hardline responses from governments and law enforcement.

NCC Group’s managed detection and response service and its cyberincident response team noted the LockBit gang was involved in 846 attacks last year, a 94% increase in activity compared to 2021. The group’s activity peaked in April with 103 attacks and ahead of the launch of its LockBit 3.0 ransomware software launch, NCC Group noted in its annual "Threat Monitor" report.

LockBit was also the first ransomware-as-a-service operation to offer a bug bounty program, which it launched in June 2022.

The BlackCat group also slipped past Conti, accounting for 8% of NCC Group’s monitored attacks in 2022. That group's activity peaked in December, with 30 incidents discovered.

Russian-affiliated Conti was responsible for 7% of attacks last year, down from 21% in 2021. NCC Group noted it did not find any attacks from Conti during the second half of last year. "This reduction in activity coincided with the introduction of new group BlackBasta, believed to be associated with – or a replacement for – Conti," NCC Group added.

NCC Group Finds a Slight Dip in Ransomware

The security firm claimed monitored ransomware attacks dipped 5% overall last year to a total of 2,531 attacks. However, it noted this was likely due to more targeted countermeasures.

“Despite this slight dip in ransomware attacks, this does not mean we collectively declare ‘job done,'" Matt Hull, NCC Group’s global head of threat intelligence, said in a statement. "Indeed, this decline in attack volume and value is probably in part due to an increasingly hardline, collaborative response from governments and law enforcement, and of course the global impact of the war in Ukraine.”

“As a result, we have witnessed several coordinated operations in 2022 that saw arrests of key members of prolific cybercriminal operatives, as well as the disbanding of long-established groups,” Hull added.

The most recent action was the United States and the United Kingdom, sanctioning seven individuals involved in the Russia-based Trickbot cybercrime gang. Security vendor CrowdStrike noted those individuals are members of the Wizard Spider cybercriminal group.

“While Wizard Spider’s operations have significantly reduced following the demise of Conti in June 2022, these sanctions will likely cause disruption to the adversary’s operations while they look for ways to circumvent the sanctionsm" Adam Meyers, head of intelligence at CrowdStrike, explained to SDxCentral in an email. "Often, when cybercriminal groups are disrupted, they will go dark for a time only to rebrand under a new name.”

The NCC Group report also showed a notable surge in ransomware attacks between February and April 2022, coinciding with the start of the Russia-Ukraine war when prominent threat actor LockBit ramped up activity.

“The threat landscape has been heavily influenced by the conflict between Russia and Ukraine, with a whole arsenal of offensive cyber capabilities, from [distributed denial of service] to malware, deployed by criminals, hacktivists, and even other nations,” Hull noted. “Though perhaps not the ‘cybergeddon’ that some expected from the next big global conflict, we are seeing state-sponsored attacks ramp up with cyber warfare proving to be critical in this hybrid cyber-physical battlefield."