Lockbit Dominates Threat Landscape as Conti Offshoots Fuel Global Ransomware Resurgence

Global cybersecurity researchers have recorded a sharp and concerning resurgence in ransomware attacks, driven aggressively by established ransomware-as-a-service (RaaS) operations and the decentralized remnants of fractured cybercrime syndicates. According to threat intelligence data released by the NCC Group, July witnessed a dramatic 47 percent month-over-month increase in successful ransomware campaigns globally, rebounding from a brief diplomatic and law enforcement-induced lull observed earlier in the spring.
At the epicentre of this malicious surge is Lockbit—specifically its iteration Lockbit 3.0—which has cemented its status as the most prolific and pervasive ransomware gang operating today. Concurrently, the landscape is being radically reshaped by the sudden, aggressive rise of Hiveleaks and BlackBasta, two distinct operations directly tied to the fallout and splintering of the once-dominant Conti cartel. Security analysts warn that these evolving dynamics signal a permanent shift in how cybercriminal enterprises adapt to geopolitical pressure, law enforcement interventions, and global sanctions.
Main Facts and the July Threat Landscape
The NCC Group’s comprehensive monthly Threat Pulse report, compiled by actively monitoring underground leak sites and scraping real-time victim disclosures, documented 198 successful ransomware attacks worldwide in July. This represents a significant bounce back from June figures, though it remains below the peak activity levels recorded earlier in the year during March and April, when campaigns approached nearly 300 incidents per month.
Lockbit accounted for an astounding 62 attacks in July alone. This figure represents an increase of ten attacks compared to the previous month and amounts to more than twice the combined output of the second and third most active cybercriminal groups. Security researchers emphasize that Lockbit 3.0 has successfully maintained an expansive operational footprint, utilizing sophisticated affiliates, continuous platform upgrades, and robust extortion frameworks to target organizations across multiple sectors, including manufacturing, healthcare, finance, and critical infrastructure.
Behind Lockbit, the threat landscape is increasingly defined by the explosive growth of Hiveleaks and BlackBasta. Hiveleaks executed 27 attacks in July, representing an astronomical 440 percent surge compared to June. Meanwhile, BlackBasta claimed 24 attacks, marking a 50 percent increase over the same period. Combined, these two rising factions are filling the vacuum left by historical enforcement actions, proving that modern cybercrime syndicates are exceptionally resilient, highly modular, and capable of rapid structural rebirth.
Chronology of the 2022 Ransomware Shift
To understand the current dominance of Lockbit and the sudden emergence of Hiveleaks and BlackBasta, cybersecurity analysts trace a timeline of escalating pressure from Western governments against Russian-speaking cybercrime cartels.
The turning point for the contemporary threat landscape began in late 2021 and early 2022, characterized by coordinated international law enforcement raids, targeted arrests, and severe financial sanctions. The most monumental disruption occurred in the wake of Russia’s invasion of Ukraine, when Conti—widely regarded as the world’s most formidable and profitable ransomware syndicate—publicly declared its allegiance to the Russian government. This political alignment triggered massive internal dissent, resulting in massive data leaks by disgruntled members, including the exposure of source code, internal chat logs, and operational infrastructure.
Recognizing the vulnerability of the fractured syndicate, the United States Department of State escalated its counter-offensive in May by launching the Rewards for Justice program. The U.S. government offered up to $15 million in financial bounties for actionable information leading to the identification, location, or disruption of key Conti leadership figures and co-conspirators.
Faced with intense international scrutiny, asset freezes, and a multi-million-dollar bounty on their heads, the core leadership of Conti made the strategic decision to officially dissolve the monolithic brand. However, rather than exiting the illicit trade, the operatives chose a decentralized approach. They dispersed into smaller, agile cells, transitioning existing affiliates and establishing new operational strains. By June, these restructured groups began stabilizing their command-and-control frameworks. By July, they had fully operationalized their new identities, culminating in the sharp spike in attacks recorded by threat intelligence analysts.
Supporting Data and RaaS Mechanics
The mechanics behind this month-over-month surge lie in the refinement of the ransomware-as-a-service (RaaS) business model. RaaS operates similarly to legitimate software subscription models, where core developers—often referred to as group administrators—build, maintain, and update malicious encryption software and negotiation portals, while independent affiliates handle the execution of network intrusions, privilege escalation, and data exfiltration.
Lockbit operates as one of the most mature RaaS enterprises in existence. By continuously refining their platform—culminating in the launch of Lockbit 3.0, which introduced bug bounty programs for hackers, improved evasion techniques, and diversified cryptocurrency payment mechanisms—the group has consistently attracted top-tier affiliates. These affiliates leverage Lockbit’s robust infrastructure to launch targeted attacks, splitting the illicit proceeds with the core developers.
The rapid ascendancy of Hiveleaks and BlackBasta demonstrates how effectively the former Conti apparatus translated its existing network of affiliates and technical expertise into new operational brands. According to NCC Group researchers, Hiveleaks operates primarily as an affiliate network that has absorbed former Conti operators, while BlackBasta functions as a direct replacement strain utilizing advanced techniques originally pioneered by the Conti syndicate.
The data illustrates a clear consolidation of power: while numerous smaller, opportunistic groups exist, the vast majority of global ransomware volume is now concentrated among a handful of highly organized, well-funded syndicates that treat cybercrime as a professional enterprise complete with human resources, customer service desks for ransom negotiations, and quality assurance testing for malware payloads.
Official Responses and Geopolitical Implications
Governments and international law enforcement agencies have not remained passive in the face of this persistent cyber threat. The deployment of multimillion-dollar bounties by the United States Department of State underscores a broader strategic shift: treating elite ransomware operators not merely as common hackers, but as transnational security threats comparable to organized crime cartels and state-sponsored espionage units.
Law enforcement agencies, including the United States Federal Bureau of Investigation (FBI), the UK’s National Crime Agency (NCA), and Europol, have increasingly shifted their focus toward disrupting the financial infrastructure that underpins RaaS operations. This includes seizing cryptocurrency exchange accounts used for laundering ransom payments, dismantling underground forum infrastructure, and issuing urgent cybersecurity advisories to private sector entities.
Despite these enforcement victories, cybersecurity experts and industry analysts note significant challenges. The decentralized nature of RaaS means that taking down a primary brand or capturing core developers often causes a temporary dip in activity, but it frequently sparks a Hydra-like effect. As demonstrated by the Conti fallout, dismantling a major syndicate leads directly to the proliferation of multiple splinter groups—such as Hiveleaks and BlackBasta—which ultimately expand the overall attack surface and increase total campaign volume.
Furthermore, geopolitical tensions have created safe havens for cybercriminals operating within certain jurisdictions, complicating international extradition and cooperative law enforcement efforts. Consequently, Western intelligence agencies and cybersecurity firms emphasize that defensive posture must shift heavily toward proactive resilience within private and public sector networks.
Broader Impact and Implications for Organizations
The implications of July’s threat intelligence data for global organizations are profound. The stark resurgence of attacks—spurred by Lockbit’s continued dominance and the successful restructuring of Conti remnants—proves that corporate complacency remains the primary vulnerability exploited by threat actors.
Organizations can no longer rely solely on traditional perimeter security or basic antivirus solutions. Ransomware operators have evolved to utilize Living off the Land (LotL) techniques, legitimate administrative tools, and advanced social engineering to bypass standard defenses, making detection increasingly difficult during the initial phases of an intrusion.
Security leaders are being urged to adopt a comprehensive zero-trust architecture, enforce multi-factor authentication (MFA) across all enterprise access points, maintain immutable and regularly tested offline backups, and implement continuous network monitoring to identify anomalous data exfiltration before encryption occurs.
As the cybersecurity community looks toward the remainder of the year, researchers warn that the structural evolution of groups like Hiveleaks and BlackBasta is likely complete. With these factions fully settled into their new operational modes, threat intelligence analysts anticipate that attack volumes will maintain their upward trajectory, reinforcing the reality that ransomware remains one of the most pervasive, profitable, and disruptive security challenges of the modern digital economy.






