Article Banner Image

Threat Intelligence

May 17, 2023

Q1 2023 Threat Landscape Report: Ransomware Groups Splinter, Swarm Professional Services

Kroll’s findings for Q1 2023 highlight fragmented threat actor groups and a continued evolution in attack methods and approaches, which, alongside other key shifts in behavior, have concerning implications for organizations in many sectors.

In Q1 2023, Kroll observed a 57% increase in the overall targeting of the professional services sector from the end of 2022. Ransomware propelled this increase as the sector, particularly legal firms, was the most likely target of extortion and encryption attacks in Q1.

Overall, ransomware accounted for 30% of Q1 cases and 26% of email compromise cases, both remaining closely aligned with the 2022 levels. In Q1, Kroll noted a 56% increase in the number of unique ransomware variants observed. While well-known ransomware-as-a-service (RaaS) operations such as LOCKBIT continue to dominate the ransomware landscape, Kroll observed a number of lesser-known variants during the quarter. Some of these were new but others were established groups that had not been observed for several quarters. The rise in these lesser-known variants, specifically ones such as XORIST, highlights the number of independent attackers conducting ransomware operations outside of the established RaaS groups. 

 

Phishing continues to lead the pack when it comes to initial access across all cases. Drilling into ransomware cases shows that legacy vulnerabilities such as ProxyShell and Log4j are more likely to be exploited to gain a foothold into the system. 

No matter how actors get into a network, data around toolkit deployment during the Kroll Intrusion Lifecycle indicates that actors are using exfiltration tools as standard across a wide variety of threat incident types. As such, enabling organizations to detect actions within a network that denotes staging for exfiltration may help stop attackers in their tracks.

Q1 2023 Timeline

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...