Akamai’s latest report showed a shift in ransomware strategies — an uptick in the exploitation of zero-day and one-day vulnerabilities. The vendor also found ransomware groups are increasingly targeting file exfiltration as their primary means of extortion.

The report is based on data collected from the leak sites of approximately 90 different ransomware groups over a period of 20 months, from October 1, 2021, to May 31, 2023.

It found ransomware attackers are pivoting from phishing to vulnerability abuse, which has surged both in scope and sophistication. These groups are becoming more aggressive in both extortion and vulnerability exploitation; for example, they started developing zero-day attacks and bug bounty programs in house. They are also willing to pay other hackers for vulnerabilities that can be used in attacks, or to acquire access to their intended targets via initial access brokers, according to the report.

The zero-day and one-day vulnerability abuse has led to a 143% increase in total ransomware victims, Akamai researchers found.

“The increasing number of web application vulnerabilities are being significantly abused to cast a wider net, and applications that hold sensitive information are being leveraged as another addition to extortion,” researchers wrote in the report. “Zero-day and one-day vulnerabilities are also becoming a staple in specific ransomware groups’ cookbooks, with some security flaws exploited in proprietary or uncommon platforms or software.”

Additionally, ransomware groups are finding more success in data-theft extortion and moving away from their initial tactic of encryption to gain the upper hand against victims that rely on backups. File exfiltration often is combined with other extortion methods including threatening or harassing the victim’s customers or partners.

“Indeed, ransomware has evolved into a cybercriminal enterprise that goes beyond holding files or systems hostage,” researchers wrote, adding that this shift indicates that traditional file backup solutions may no longer be adequate to safeguard against these increasingly sophisticated attacks.

Higher risk of a second attack for previously victimized orgs

Akamai’s research found organizations that have fallen victim to multiple ransomware attacks are more than six times more likely to experience another attack within the first three months compared to a longer timeframe, which highlights the importance of preventing and mitigating initial ransomware attacks.

While the victim is busy addressing the first attack, other ransomware groups potentially scouting for targets and observing the movements of their competitors can seize this chance to attack the same company. For instance, the Royal ransomware group targeted the same entity nearly four months after Hive had initially attacked it, researchers noted.

In some other cases, the same group may target the same business twice, even over a year apart, which may indicate the victim did not entirely remove the threat from their network, whether that was related to a backdoor or specific tools. For example, LockBit attacked a real estate business in 2021 and again in 2023.

Researchers warned in the report: “Unfortunately, being attacked once and paying the ransom does not guarantee that your organization is safe. Rather, it increases your likelihood of being hit again by the same group or, worse, by multiple groups.”

They added if the victim organizations have not resolved the initial security gaps in their perimeter or vulnerabilities that were exploited in the first attacks, there's a good chance they will be exploited again. “And it does not help if the victim chooses to comply with the ransom demands, as they may then be viewed as potential targets by the same group and others.”

Smaller orgs are more targeted for ransomware

Akamai researchers highlighted another trend based on the data in the report: smaller companies are being targeted more frequently, with organizations reporting revenues of up to $50 million making up 65% of the victims.

Despite the common assumption that larger companies are more likely to be targeted due to their higher potential payoff, the analysis paints a different picture. The report showed larger organizations with revenues above $500 million account for only 12% of the victims.

Researchers suggest that smaller organizations are more likely to be targeted because their limited security resources make them more vulnerable to attack, while they have the ability (and motivation) to pay the ransom to avoid business disruption and potential loss of revenue. The report showed more than 17% of victims are businesses with a revenue range of $51 million to $250 million.

However, this does not mean that larger companies are safe. Even though a smaller percentage of them are affected, the impact of an attack on a large organization can also be disruptive due to the potential for higher ransom payments and larger volumes of sensitive data at risk, the report noted.