By Global Cybersecurity Desk
Published: August 2022


Executive Overview

The global threat landscape has shifted dramatically over the mid-year mark, characterized by a potent resurgence in ransomware operations orchestrated by both entrenched digital extortion syndicates and newly forged splinter factions. According to comprehensive threat intelligence data released by the NCC Group, July witnessed a staggering 47 percent month-over-month increase in successful ransomware campaigns, halting a brief spring lull and signaling a worrying maturation of the Ransomware-as-a-Service (RaaS) ecosystem.

At the epicenter of this malicious activity is Lockbit (specifically operating under its iteration, Lockbit 3.0), which has cemented its status as the most prolific and dangerous cybercrime syndicate of the year. In July alone, Lockbit was attributed to an unprecedented 62 successful attacks—outpacing its nearest competitors by more than double.

Simultaneously, the threat ecosystem is witnessing the aggressive mutation and redeployment of operators formerly aligned with Conti, the infamous Russian-linked cybercrime cartel that fractured earlier in the year under intense geopolitical and law enforcement pressure. Two prominent successors—Hiveleaks and BlackBasta—have surged into the upper echelons of global threat activity, recording hyper-accelerated growth rates of 440 percent and 50 percent respectively between June and July.

This in-depth investigative report examines the mechanics behind July’s threat spike, analyzes the dominance of Lockbit 3.0, tracks the phoenix-like rebirth of Conti’s network, and evaluates what enterprise security leaders must do to defend against this evolving wave of digital extortion.


Detailed Chronology: Tracing the Mid-Year Ransomware Trajectory

To fully understand the gravity of July’s threat metrics, cybersecurity analysts must contextualize the trajectory of the first half of 2022. The threat landscape has not followed a linear path; rather, it has been defined by volatile spikes, strategic organizational realignments, and high-profile international law enforcement interventions.

Q1 2022: The Spring High-Water Mark

The year began with relentless momentum for cyber extortion groups. Driven by mature RaaS models, affiliates launched massive waves of attacks targeting critical infrastructure, healthcare providers, educational institutions, and multinational corporations. During both March and April, threat intelligence monitors recorded nearly 300 successful ransomware campaigns per month. These figures represented historic highs, driven largely by monolithic operations like Conti, which at the time operated with near-impunity and commanded massive pools of affiliate hackers.

May 2022: Geopolitical Pressure and the Collapse of Conti

The momentum abruptly shifted in May. Facing mounting pressure from Western governments—and specifically the United States Department of State—the infrastructure supporting Russian-backed syndicates began to crumble. In a landmark move, the U.S. government issued a multi-million-dollar bounty program, offering up to $15 million for actionable intelligence capable of identifying or bringing to justice the key co-conspirators of the Conti ransomware variant.

This intense spotlight, coupled with internal fractures caused by the group’s public alignment with the Russian government following the invasion of Ukraine, forced Conti into an unprecedented operational collapse. The centralized brand was quietly retired, and its massive infrastructure, codebase, and affiliate networks were forced to scatter.

June 2022: The Interlude and the Dip

Throughout June, the global threat landscape experienced a noticeable lull. NCC Group metrics noted a dip in total attacks as threat actors went "underground" to restructure. Affiliates previously loyal to Conti found themselves orphaned, searching for new administrative platforms, negotiating teams, and leak sites. During this transitional month, total global campaigns receded to roughly 135, creating a false sense of security across corporate boardrooms.

July 2022: The Resurgence and Re-emergence

The breathing room was short-lived. By July, NCC Group’s telemetry recorded 198 successful ransomware campaigns—a fierce 47 percent rebound. Researchers tracking the leak sites observed that the dip was merely a period of organizational adaptation. The operatives who once comprised Conti had successfully settled into new operational modes, while existing heavyweights like Lockbit capitalized on the market disruption to expand their operational reach.


Supporting Context & Metrics: Quantifying the Threat Landscape

The NCC Group’s Monthly Threat Pulse report relies on empirical data gathered through continuous, active monitoring of underground forums, dark web leak sites, and extortion portals. By systematically scraping victim details as soon as they are published by threat actors, researchers maintain an accurate ledger of successful compromises where organizations refused to pay ransoms and subsequently had their proprietary data leaked.

The Numbers That Define July 2022

Rank Ransomware Group / Variant July 2022 Attacks June 2022 Attacks Month-over-Month Growth / Trend
1 Lockbit (Lockbit 3.0) 62 52 +19.2% (Dominant Leader)
2 Hiveleaks 27 5 +440% (Explosive Rise)
3 BlackBasta 24 16 +50% (Steady Expansion)
Others / Unaffiliated 85 62 +37%
Total Global Campaigns 198 135 +47.4% Overall Increase

Lockbit 3.0: The Apex Predator of Cyber Extortion

Lockbit’s performance in July was nothing short of dominant. Responsible for 62 attacks, the group accounted for nearly one-third of all global ransomware incidents tracked during the month. This represents ten more attacks than Lockbit achieved in June, and more than double the combined output of its two closest competitors, Hiveleaks and BlackBasta.

Lockbit 3.0 (also known as Lockbit Black) represents a significant technical and procedural evolution from its predecessors. Released in early 2022, the 3.0 framework introduced a bug bounty program—ironically mimicking legitimate corporate software development cycles—inviting external hackers to audit its code and find vulnerabilities in its encryption payload. Furthermore, Lockbit introduced enhanced evasion techniques, improved lateral movement tools, and a redesigned extortion portal that incorporates cryptocurrency donation features and public voting on leaked corporate data.

Security analysts at NCC Group issued a stark warning regarding the syndicate: "Lockbit 3.0 maintains its foothold as the most threatening ransomware group, and one with which all organizations should aim to be aware of and prepared against."

The Conti Diaspora: Hiveleaks and BlackBasta

While Lockbit held the top spot, the most alarming trend in the July data was the meteoric rise of groups with direct lineage to the defunct Conti syndicate.

  1. Hiveleaks (Hive): Recording 27 attacks in July compared to just 5 in June, Hiveleaks experienced a staggering 440 percent increase in activity. Long suspected of maintaining cooperative ties with Conti affiliates, Hiveleaks appears to have absorbed a significant portion of Conti’s displaced human capital—experienced negotiators, initial access brokers, and veteran programmers.
  2. BlackBasta: Emerging aggressively in the spring, BlackBasta logged 24 attacks in July, up 50 percent from June’s 16. Cyber intelligence researchers have noted striking operational similarities between BlackBasta’s deployment methods and historical Conti campaigns, leading analysts to classify BlackBasta as a direct replacement strain engineered by core Conti leadership to bypass international sanctions and law enforcement tracking.

Combined, these two Conti-adjacent groups accounted for 51 successful attacks in July, proving that the dissolution of a single brand name does little to eradicate the underlying human threat actors. As NCC Group researchers noted, "It appears that it has not taken long for Conti’s presence to filter back into the threat landscape, albeit under a new identity."


Official Statements and Expert Analysis

The rapid evolution of the RaaS ecosystem has triggered urgent discussions among cybersecurity policymakers, incident response firms, and enterprise risk officers.

In its official July 2022 threat briefing, the NCC Group research team emphasized that the traditional security perimeter is no longer sufficient to deter modern cyber syndicates. Commenting on the structural shifts in the underground economy, lead threat intelligence analysts noted:

"The ransomware-as-a-service model has proven exceptionally resilient. When governments apply pressure to a major hub like Conti, the enterprise does not simply vanish. Instead, it undergoes a process of corporate restructuring, much like a traditional business syndicate facing regulatory hurdles. The skilled operators, affiliates, and extortionists simply migrate to pre-existing platforms like Lockbit or spin up agile, independent offshoots like BlackBasta and Hiveleaks."

Law enforcement agencies, including the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the UK’s National Cyber Security Centre (NCSC), have echoed these warnings. Intelligence-sharing partnerships have increasingly focused on mapping out the financial trails and cryptocurrency laundering networks utilized by RaaS administrators.

However, experts caution that arrests and sanctions remain reactive measures. The core vulnerability lies in corporate digital hygiene. According to incident response specialists, the vast majority of Lockbit and BlackBasta compromises do not rely on zero-day exploits; rather, they exploit fundamental security hygiene failures—such as unpatched VPN gateways, weak Remote Desktop Protocol (RDP) configurations, and a lack of multi-factor authentication (MFA) across internal employee accounts.


Future Outlook: What to Expect as We Move into August and Beyond

As the cybersecurity community turns its attention toward the remainder of the third quarter, the consensus among threat intelligence analysts is clear: the upward pressure on ransomware attack volumes is expected to continue.

1. Consolidation and Maturation of New Factions

Now that the Conti diaspora has successfully reorganized into structured entities like BlackBasta and fortified existing alliances with Hiveleaks, these groups have stabilized their operations. Having established their new operational rhythms, their total successful compromises are projected to increase further throughout August and September. Enterprises should anticipate more aggressive double- and triple-extortion tactics, where stolen data is not only leaked but weaponized against customers, partners, and shareholders of targeted organizations.

2. The Unyielding Hegemony of Lockbit

Lockbit shows no signs of slowing down. With a well-funded development cycle, dedicated affiliate networks, and a highly reliable encryption infrastructure, Lockbit 3.0 remains the gold standard of cybercrime efficiency. Analysts warn that Lockbit will likely continue to absorb disgruntled affiliates from smaller, failing ransomware strains, further cementing its monopoly over the global extortion market.

3. Regulatory Shifts and Mandatory Reporting

In response to the relentless wave of attacks, governments worldwide are moving closer to enacting stringent, mandatory incident reporting laws. These regulations aim to eliminate the silence surrounding successful ransomware attacks, enabling intelligence agencies to build comprehensive profiles of threat actor tactics, techniques, and procedures (TTPs). However, compliance with regulatory frameworks will place an additional operational burden on corporate IT and legal departments.

Recommendations for Enterprise Security Leaders

In light of the NCC Group’s alarming July metrics, organizations must adopt an aggressive, defense-in-depth posture:

  • Harden Remote Access: Eliminate exposure to legacy RDP ports directly facing the public internet. Enforce phishing-resistant multi-factor authentication (MFA) across all corporate entry points and employee accounts.
  • Rigorous Patch Management: Prioritize vulnerability remediation, focusing particularly on known exploited vulnerabilities cataloged by CISA. Threat actors continuously scan for unpatched perimeter devices to gain initial access.
  • Immutable Backups: Maintain isolated, offline, and immutable backups of critical corporate data. Regularly test disaster recovery and restoration procedures to ensure business continuity without bowing to ransom demands.
  • Continuous Threat Intelligence Integration: Subscribe to real-time threat intelligence feeds to monitor indicators of compromise (IoCs) associated with Lockbit 3.0, BlackBasta, and Hiveleaks.

As the lines between state-sponsored cyberespionage and financially motivated cybercrime continue to blur, vigilance, adaptability, and proactive defense remain the only viable shields against the summer ransomware resurgence.

By Nana

Leave a Reply

Your email address will not be published. Required fields are marked *