Resurgence of Global Ransomware Attacks Led by LockBit and Conti Offshoots Signal a Dangerous New Era in Cybercrime

The global cybersecurity landscape has witnessed a significant and troubling resurgence in ransomware activity during the summer of 2022, marking an end to a brief period of relative calm. Following a noticeable dip in successful exploitations during the late spring, new data indicates that cybercriminal syndicates have successfully reorganized, with the notorious LockBit group maintaining a dominant lead. This revival is not merely a return to previous levels of aggression but represents a strategic evolution in the Ransomware-as-a-Service (RaaS) model. According to the latest monthly Threat Pulse report released by the NCC Group, the month of July saw a staggering 47 percent increase in successful ransomware campaigns compared to June, signaling that the threat actor ecosystem has finalized a period of internal restructuring.
The statistics gathered by researchers through the active monitoring of leak sites and the scraping of victim details reveal that 198 successful ransomware attacks were publicly documented in July. While this figure remains below the record-breaking peaks of March and April, where nearly 300 monthly campaigns were recorded, the trajectory suggests a sharp upward trend. The driving force behind this surge is LockBit 3.0, a group that has solidified its position as the most prolific and technologically advanced threat to enterprise security globally. In July alone, LockBit was responsible for 62 documented attacks, a significant increase from the 52 attacks recorded in June. This volume of activity is more than double the combined output of its two closest competitors, underscoring a level of operational scale that few other groups can match.
The Dominance of LockBit 3.0 and the Innovation of Extortion
LockBit’s continued dominance is largely attributed to the launch of "LockBit 3.0," also known internally by the group as "LockBit Black." This iteration of their software was released with a high degree of fanfare within the cybercriminal underground, accompanied by the industry’s first-ever "bug bounty" program for a ransomware strain. By offering rewards to researchers and hackers who could identify vulnerabilities in their encryption code or suggest improvements to their leak site, LockBit adopted the professionalized standards of legitimate software corporations.
The group’s success is further bolstered by its aggressive affiliate recruitment. LockBit 3.0 operates on a RaaS model where the core developers provide the malware and infrastructure, while "affiliates" carry out the actual intrusions. This decentralized approach allows the group to scale rapidly across multiple geographic regions and industries simultaneously. Security analysts note that LockBit’s "Rules of Engagement" often allow for the targeting of a wide array of sectors, though they ostensibly prohibit attacks on critical infrastructure that could lead to loss of life—a rule that is frequently ignored or loosely interpreted by its affiliates.
The Ghost of Conti: The Rise of Hiveleaks and BlackBasta
While LockBit occupies the top spot, the most significant structural shift in the threat landscape involves the remnants of the Conti ransomware group. Previously the world’s most formidable cybercrime syndicate, Conti officially disbanded earlier this year following a series of internal data leaks and intense pressure from international law enforcement. However, the July data confirms that Conti has not disappeared; rather, it has metastasized into several smaller, more agile entities.
Two primary offshoots, Hiveleaks (often referred to simply as Hive) and BlackBasta, have emerged as the second and third most active groups in the wake of Conti’s fragmentation. Hiveleaks recorded 27 attacks in July, representing a massive 440 percent increase from its June activity. BlackBasta followed closely with 24 attacks, a 50 percent rise over the previous month. Researchers suggest that these groups are either direct rebrandings of Conti sub-units or are heavily populated by former Conti operators who brought their expertise, access credentials, and technical infrastructure to these "new" ventures.
BlackBasta, in particular, has caught the attention of the cybersecurity community due to its rapid ascent. Since its first appearance in April 2022, it has displayed a level of sophistication in its double-extortion tactics—where data is both encrypted and stolen for ransom—that typically takes years for new groups to develop. This professionalized execution strongly supports the theory that BlackBasta is a "replacement strain" designed to allow Conti members to continue operations under a name that is not yet subject to the same level of international sanctions and law enforcement scrutiny.
A Chronology of the 2022 Ransomware Flux
The volatility observed in the middle of 2022 can be traced back to a specific timeline of geopolitical events and law enforcement interventions. In early 2022, the ransomware market was relatively stable, dominated by Conti and LockBit. However, the onset of the Russia-Ukraine conflict in February created a rift within the cybercriminal community. When Conti’s leadership publicly declared their support for the Russian government, a Ukrainian researcher leaked years of internal chat logs and the group’s source code, an event known as "ContiLeaks."
This breach of internal security, combined with the U.S. Department of State’s announcement in May of a $15 million reward for information leading to the identification or location of Conti’s leadership, made the Conti brand toxic. The subsequent "dip" in ransomware activity observed in May and June was the result of this transition period. Threat actors were forced to go underground, migrate their servers, and establish new identities to avoid being linked to the Conti brand and the associated U.S. sanctions.
By July, this restructuring phase appeared to reach completion. The "bounce" in attack numbers indicates that the former Conti affiliates have settled into their new modes of operation. By operating under multiple banners like Hive, BlackBasta, and Karakurt, the syndicate has effectively diversified its risk. If one brand becomes too "hot" for law enforcement, the operators can simply shift their focus to another, ensuring the continuity of their criminal enterprise.
Sector Analysis and Geographic Targeting
The resurgence in July was characterized by a broad targeting strategy, though certain sectors remained more vulnerable than others. The industrial sector continues to be the primary target for ransomware groups, accounting for nearly one-third of all attacks. This is due to the high pressure on industrial firms to maintain uptime, making them more likely to consider ransom payments to avoid costly operational shutdowns. The retail and technology sectors followed as the next most targeted industries.
Geographically, the United States remains the most targeted nation, a trend that has persisted for several years. However, July saw a notable increase in attacks targeting organizations in Europe and the Asia-Pacific region. This geographic expansion is likely a result of LockBit’s global affiliate network, which recruits hackers from various linguistic and cultural backgrounds to facilitate local intrusions.
Official Responses and Law Enforcement Strategy
The rise of these groups has prompted a renewed focus from international authorities. The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside the FBI and international partners like Europol, have shifted their strategy toward "active disruption." Rather than focusing solely on arrests, which are difficult given that many of these actors reside in non-extradition jurisdictions like Russia, law enforcement is increasingly targeting the financial and technical infrastructure of these groups.
The $15 million bounty offered by the U.S. State Department’s Rewards for Justice program remains a key tool in this effort. By creating financial incentives for "honor among thieves" to erode, the government aims to sow distrust within these syndicates. In response to the July surge, several government spokespeople have reiterated that paying ransoms only fuels the cycle of innovation for groups like LockBit, enabling them to fund the development of even more sophisticated encryption tools.
Broader Impact and Future Implications
The implications of the July resurgence extend beyond the immediate financial loss of the victimized companies. The evolution of LockBit 3.0 and the Conti offshoots signifies that the ransomware "business model" is more resilient than previously thought. The ability of these groups to reorganize and increase their attack volume by nearly 50 percent in a single month suggests that they have developed a highly efficient pipeline for identifying and exploiting vulnerabilities.
Furthermore, the rise of the "initial access broker" (IAB) market has streamlined the ransomware process. These brokers specialize in gaining entry into corporate networks and then selling that access to ransomware groups like BlackBasta or Hive. This specialization allows ransomware operators to focus entirely on the deployment of malware and the negotiation of ransoms, significantly increasing their operational tempo.
As the industry moves into the latter half of the year, experts predict that the figures will continue to climb. The fragmentation of large groups into smaller, more numerous entities makes the task of cybersecurity defenders more complex. Instead of defending against one or two dominant methodologies, organizations must now prepare for a diverse array of tactics, techniques, and procedures (TTPs) employed by a growing list of Conti-linked variants.
The July data serves as a stark reminder that the ransomware threat is not diminishing but is instead becoming a permanent, evolving feature of the global digital economy. Organizations are urged to move beyond basic perimeter defense and adopt "zero trust" architectures, rigorous data backup protocols, and comprehensive incident response plans. With LockBit 3.0 maintaining its foothold and new strains emerging from the ashes of Conti, the "summer of ransomware" may well be a prelude to an even more volatile autumn in the cyber domain.







