NCC Group reports ransomware rise as supply chain risks grow | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


NCC Group reported a rise in global ransomware attacks in the second quarter, with its latest cyber threat analysis recording 2,229 incidents.

That was 3% higher than the 2,165 attacks recorded in the first quarter.

The figures show several established ransomware groups remained dominant even as newer actors gained ground. Qilin was the most active threat group for the fifth consecutive quarter, accounting for 301 attacks in Q2, or 14% of the global total.

Even so, that marked an 11% decline from 340 attacks in the first quarter. In June alone, Qilin was linked to 79 attacks, equal to 12% of the monthly total.

Behind Qilin, The Gentlemen recorded 238 victims in the quarter, while DragonForce ranked third with 145. Attacks linked to both DragonForce and The Gentlemen rose 60% from the first quarter to the second.

Akira, another established ransomware group, launched 127 attacks during Q2, down 34% from 191 in the previous quarter.

KryBit also entered the top 10 most active ransomware groups over the past three months, indicating fresh competition in a threat landscape still led by familiar names.

Monthly activity remained high at the end of the quarter. June saw 665 ransomware attacks globally, up 22% from the same month a year earlier.

Sector focus

Industrial companies remained the most targeted sector in the second quarter, accounting for 30% of attacks worldwide. Consumer Discretionary and Information Technology followed, together making up 23% of incidents. Both were also among the most targeted sectors in June.

That month, industrial organisations faced 183 attacks, or 28% of the global total. Consumer Discretionary businesses saw 166 attacks, or 25%, while Information Technology accounted for 63 attacks, or 9%.

Geographically, North America remained the main target for ransomware groups, recording 980 attacks in Q2, equivalent to 44% of the global total.

Europe ranked second with 579 attacks in the quarter, or 26%. In June, North America recorded 275 attacks, or 41%, followed by Europe with 153, or 23%, and Asia with 133, or 20%.

Supply chain risks

The report also pointed to a rise in supply chain attacks, with threat groups increasingly targeting software development ecosystems rather than organisations directly. The approach centres on compromising software and development tools used across large numbers of businesses, allowing one breach to spread to multiple downstream victims.

NCC Group identified TeamPCP as one of the more prominent groups associated with this trend. Its campaigns showed how compromised software dependencies and development workflows could be used to infiltrate organisations before attacks are detected.

Another area of concern was the continued targeting of corporate virtual private networks and internet-facing edge devices. Attackers ranging from opportunistic hackers to ransomware-as-a-service operators and nation-state-backed advanced persistent threat groups continued to exploit software weaknesses to gain unauthorised access.

Vulnerabilities affecting certain VPN products or their manufacturers featured prominently in threat intelligence alerts issued in the first half of the year. Many of those alerts were rated high or critical severity.

Matt Hull, vice president and head of cyber intelligence and response at NCC Group, commented on the broader pattern in the data.

“Supply chain attacks continue to be one of the most attractive routes for threat actors to cause significant operational, financial and reputational damage to organizations. We have seen these attacks continue to rise in scale and sophistication, and businesses should therefore ensure monitoring and resilience is continuous, rather than ad hoc. Although there has not been a material rise in ransomware volume in the last quarter, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target. Alongside ongoing geopolitical tensions, rapidly evolving AI capabilities and increasingly sophisticated attack methods, organizations must remain resilient and proactive in their approach to cyber security, treating it as the board-level issue it is,” said Hull.

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW