By Global Cybersecurity Desk
Published: August 2022


Executive Overview

The global cybersecurity landscape is once again flashing red. Following a brief, spring-induced lull, ransomware attacks have made a forceful resurgence, driven by a lethal combination of established ransomware-as-a-service (RaaS) cartels and newly splintered criminal syndicates. According to threat intelligence data released by the NCC Group, July witnessed a staggering 47 percent surge in successful ransomware campaigns compared to the previous month, signaling a turbulent summer for enterprise security teams, critical infrastructure operators, and public sector organizations alike.

At the epicenter of this malicious campaign is Lockbit, which continues to cement its status as the most prolific and aggressive threat group operating today. Maintaining its stranglehold on the cybercrime ecosystem, Lockbit accounted for nearly a third of all recorded attacks in July alone, outpacing its nearest competitors by a factor of two.

However, Lockbit is not acting in a vacuum. The July threat pulse highlights a profound structural shift in the underworld: the resurrection and adaptation of actors formerly aligned with Conti, the infamous Russian-speaking syndicate that fractured earlier this year under intense geopolitical and law enforcement pressure. Offshoots and affiliates of the defunct Conti gang—namely Hiveleaks and BlackBasta—have experienced meteoric rises, filling the vacuum left by their predecessor and accelerating the pace of extortion operations worldwide.

This report provides a comprehensive examination of the July threat landscape, breaking down the numbers behind the ransomware resurgence, analyzing the geopolitical factors that triggered the Conti diaspora, and exploring what organizations must do to fortify their networks against an increasingly sophisticated breed of cybercriminals.


Detailed Chronology of the Summer Wave

To understand the trajectory of the current threat environment, analysts must look backward to the spring of 2022, a period that set modern records for cyber extortion volume.

The Spring High-Water Mark

During March and April, the global threat landscape was inundated with roughly 300 successful ransomware campaigns per month. Threat actors operated with near impunity, leveraging zero-day vulnerabilities, aggressive double-extortion tactics, and sprawling affiliate networks to compromise organizations across manufacturing, healthcare, finance, and technology sectors.

The May Disruption

The momentum abruptly slowed in May, driven primarily by aggressive intervention from Western governments. Most notably, the United States Department of State ratcheted up pressure on Russian-backed cyber syndicates by issuing a reward of up to $15 million for information leading to the identification or location of key leaders and co-conspirators of the Conti ransomware variant. This high-profile financial bounty—coupled with ongoing international intelligence-sharing operations—effectively forced Conti, then the undisputed kingpin of the ransomware economy, to dissolve its centralized command structure.

For several weeks, the cybercrime ecosystem experienced a noticeable vacuum. The fragmentation of Conti caused widespread organizational paralysis among its core members, affiliates, and money-laundering cells. Attack volumes dipped as threat actors went to ground, scrambled to sanitize their infrastructure, and negotiated new alliances in underground forums.

The July Resurgence

By mid-summer, however, the dust had settled. NCC Group’s telemetry—gathered through continuous, active monitoring of underground leak sites and automated scraping of victim disclosure pages—revealed that July experienced 198 successful ransomware campaigns. While this figure remains below the hyper-active peaks of March and April, the 47 percent month-over-month increase from June demonstrates that the threat groups have successfully reorganized, retooled, and returned to business with renewed vigor.


Supporting Context & Metrics: The Numbers Behind the Threat

Data remains the ultimate source of truth in threat intelligence. The July NCC Group Threat Pulse provides granular insight into which groups are driving the resurgence and how rapidly the threat landscape is evolving.

Lockbit 3.0: The Indisputable Apex Predator

Lockbit maintained its unchallenged dominance throughout July, accounting for 62 attacks. This represents a significant escalation from the previous month, translating to a gain of ten additional victims. More impressively, Lockbit’s output in July was more than double the combined total of the second and third most prolific groups.

Operating under the RaaS model, Lockbit continues to iterate on its codebase and affiliate programs. The introduction of Lockbit 3.0 (also known as Lockbit Black) brought enhanced obfuscation techniques, a revamped bug bounty program that ironically invites security researchers to hack their platform, and improved anti-analysis features. The group’s relentless focus on operational security, rapid encryption speeds, and high-pressure psychological extortion tactics aimed at C-suite executives has ensured its status as the most persistent threat facing modern enterprises.

The Conti Diaspora: Hiveleaks and BlackBasta Surge

While Lockbit claims the crown for sheer volume, the most alarming statistical shifts belong to groups tied directly to the ashes of Conti:

  • Hiveleaks: Recorded 27 attacks in July, representing a jaw-dropping 440 percent increase compared to June figures. Researchers have identified Hiveleaks as a primary affiliate structure that absorbed displaced Conti operators seeking an established platform to launch their payloads.
  • BlackBasta: Recorded 24 attacks in July, marking a 50 percent increase month-over-month. BlackBasta is widely regarded by intelligence analysts not merely as an affiliate, but as a direct replacement strain engineered by core elements of the former Conti leadership to bypass existing security signatures and sanctions.

When combined, Hiveleaks and BlackBasta accounted for 51 attacks in July—breathing down the neck of Lockbit and proving that the dismantling of a major syndicate often leads to the proliferation of multiple, equally dangerous successor cells.

Threat Group July 2022 Attacks Month-over-Month Trend Primary Association / Origin
Lockbit (3.0) 62 +19% (vs. June) Independent RaaS Cartel
Hiveleaks 27 +440% (vs. June) Former Conti Affiliate Network
BlackBasta 24 +50% (vs. June) Conti Successor / Replacement Strain

Official Statements and Analyst Insights

The speed at which the cybercriminal underworld adapted to international sanctions and law enforcement pressure has stunned many veteran security analysts.

According to the authors of the NCC Group monthly threat pulse, the connection between government intervention, organizational restructuring, and the July attack surge is direct and causal:

"It is likely that the threat actors that were undergoing structural changes have begun settling into their new modes of operating, resulting in their total compromises increasing in conjunction. As such, it appears that it has not taken long for Conti’s presence to filter back into the threat landscape, albeit under a new identity."

The report emphasizes that while high-profile law enforcement actions—such as the U.S. State Department’s multi-million dollar bounties—are crucial for disrupting high-level command structures, they rarely extinguish the underlying motivation or technical capability of individual cybercriminals. Instead, these actions trigger a diaspora effect. Operators disperse into smaller cells, franchise their tooling to new actors, or rebrand under novel moniker banners (such as Hiveleaks and BlackBasta) to evade asset freezes, travel bans, and targeted monitoring.

Furthermore, analysts highlight the maturation of the RaaS model as a primary catalyst for sustained threat levels. Because groups like Lockbit operate franchise models, they insulate core developers from the frontline risks of deployment. Affiliates handle initial access, lateral movement, and extortion, while core developers focus entirely on feature updates, decryption reliability, and evading endpoint detection and response (EDR) agents.


Future Outlook: What to Expect in the Second Half of 2022

As the cybersecurity community moves deeper into the second half of the year, industry experts warn that organizations must prepare for an escalation in both the frequency and sophistication of ransomware attacks.

1. Continued Consolidation and Rebranding

With Conti successfully split into agile successor strains like BlackBasta and integrated into collaborative frameworks like Hiveleaks, threat intelligence researchers predict that these groups will continue to scale their operations. It would not be surprising to see these figures further increase as the summer concludes and organizations resume full operational capacity following the vacation period. Moreover, as law enforcement agencies begin to target these new monikers, security teams should anticipate further splintering and rapid rebranding exercises.

2. Evolution of Extortion Tactics

The traditional playbook of simply encrypting files and demanding Bitcoin ransom is evolving. Threat actors increasingly rely on triple extortion—combining file encryption, data exfiltration with threats to leak sensitive corporate or customer data publicly, and direct Distributed Denial of Service (DDoS) attacks against victims who refuse to enter negotiations. Lockbit and its peers are also increasingly targeting third-party supply chains, leveraging a single compromised vendor to gain downstream access to dozens of enterprise clients.

3. Recommendations for Enterprise Defense

In light of the NCC Group findings, cybersecurity leaders are urging organizations to move beyond perimeter defense and adopt a comprehensive Zero Trust architecture. Essential hardening measures include:

  • Robust Immutable Backups: Ensuring that critical data is backed up offline, encrypted, and tested regularly to guarantee rapid recovery without paying ransoms.
  • Advanced Endpoint Detection: Deploying 24/7 Managed Detection and Response (MDR) services capable of identifying abnormal lateral movement and credential dumping before payload deployment.
  • Multi-Factor Authentication (MFA): Enforcing phishing-resistant MFA across all corporate portals, VPNs, and administrative accounts to mitigate the primary initial access vectors utilized by RaaS affiliates.
  • Threat Intelligence Integration: Actively consuming real-time indicators of compromise (IoCs) associated with Lockbit 3.0, Hiveleaks, and BlackBasta to proactively hunt for threats within internal networks.

Conclusion

The July threat pulse serves as a sobering reminder of the resilience of modern cybercrime syndicates. While geopolitical pressure can disrupt criminal hierarchies, the underlying economics of ransomware ensure that threat actors will continuously adapt, mutate, and return stronger. For organizations worldwide, awareness of groups like Lockbit, Hiveleaks, and BlackBasta is no longer optional—it is a fundamental requirement for corporate survival in the digital age.

Leave a Reply

Your email address will not be published. Required fields are marked *