Lockbit Dominates the Global Ransomware Landscape as Conti Offshoots Signal a Resurgent Threat Environment

The global cybersecurity landscape experienced a significant shift in July 2022 as ransomware activities surged following a brief period of relative dormancy, with the Lockbit 3.0 group emerging as the primary driver of this renewed aggression. According to the latest monthly threat pulse released by the NCC Group, the month of July saw a 47 percent increase in successful ransomware campaigns compared to June, totaling 198 documented attacks. This resurgence is largely attributed to the stabilization of established Ransomware-as-a-Service (RaaS) organizations and the strategic rebranding of affiliates previously tied to the now-fragmented Conti syndicate. While the total number of attacks remains below the record highs observed in the spring of 2022, the rapid acceleration of activity suggests that threat actors have successfully navigated internal restructurings and are now operating with renewed efficiency.
The Dominance of Lockbit 3.0
Lockbit has solidified its position as the most prolific ransomware entity in the current threat environment. In July alone, the group was responsible for 62 successful attacks, a figure that represents nearly one-third of all documented ransomware activity for the month. This performance marks a notable increase from the 52 attacks recorded in June and places Lockbit significantly ahead of its nearest competitors. In fact, Lockbit’s volume of attacks in July was more than double the combined output of the second and third most active groups.
The sustained dominance of Lockbit is largely credited to the launch of "Lockbit 3.0," also known as "Lockbit Black." This iteration of the ransomware includes several technical refinements and a highly publicized bug bounty program—the first of its kind for a criminal organization. By offering rewards to security researchers and hackers for identifying vulnerabilities in its software, Lockbit has adopted a corporate-style quality assurance model that enhances the reliability and stealth of its encryption tools. This professionalization of cybercrime has made Lockbit an attractive partner for affiliates, ensuring a steady stream of high-profile victims across various sectors.
The Fragmentation and Rebirth of Conti
The resurgence of ransomware activity in mid-2022 is inextricably linked to the collapse and subsequent evolution of the Conti ransomware group. Once the most formidable name in the cybercrime world, Conti faced an existential crisis in May 2022 following the internal leak of thousands of chat logs and the subsequent targeting of its infrastructure by international law enforcement. The United States Department of State significantly escalated pressure on the group by offering rewards of up to $15 million for information leading to the identification and location of Conti’s leadership and its co-conspirators.
However, rather than disappearing, the expertise and manpower behind Conti have diffused into several offshoot organizations and affiliate networks. NCC Group researchers note that the May dip in attacks was likely a symptom of this structural reorganization. As these threat actors settled into new modes of operation, the volume of compromises began to climb once again. Two specific groups have emerged as the primary beneficiaries of this diaspora: Hiveleaks (Hive) and BlackBasta.
Hiveleaks recorded a staggering 440 percent increase in activity between June and July, jumping to 27 successful attacks. Simultaneously, BlackBasta saw a 50 percent increase, reaching 24 attacks. Analysts have identified strong ties between these groups and the former Conti infrastructure. Hive, while operating as an independent RaaS for some time, became a preferred destination for former Conti affiliates seeking a stable platform. BlackBasta, on the other hand, is widely viewed by researchers as a direct replacement strain for Conti, sharing similar code signatures and negotiation tactics. The rapid ascent of these two groups confirms that the threat posed by the Conti "brand" has not been neutralized but has instead evolved into a more decentralized and resilient threat.
A Chronology of the 2022 Ransomware Flux
The fluctuations in ransomware volume throughout 2022 provide a clear roadmap of how geopolitical events and law enforcement actions influence cybercriminal behavior.
- March and April 2022: Ransomware activity reached a "high-water mark," with nearly 300 successful campaigns recorded in each month. During this period, Conti was at the height of its power, frequently targeting government agencies and critical infrastructure.
- May 2022: A sharp decline in attacks occurred as Conti began to dissolve following its vocal support for the Russian invasion of Ukraine, which led to internal dissent and the "ContiLeaks" event. The U.S. government’s $15 million reward offer further incentivized the group’s dismantling.
- June 2022: Activity remained relatively low as threat actors engaged in a "quiet period" of restructuring, migrating to new RaaS platforms like Lockbit 3.0 or establishing new identities like BlackBasta.
- July 2022: The "bounce back" began in earnest. Total attacks rose to 198, driven by the operational readiness of the Conti offshoots and the aggressive expansion of Lockbit.
Sector and Geographic Distribution of Attacks
Data from the July threat pulse indicates that the industrial sector remains the primary target for ransomware operators, accounting for 32 percent of all attacks. This sector is particularly vulnerable due to the high cost of downtime and the often-outdated operational technology (OT) that manages critical production lines. The "Consumer Cyclicals" sector followed, representing 15 percent of attacks, while the technology sector accounted for approximately 11 percent.
Geographically, North America continues to be the most targeted region, bearing the brunt of 42 percent of the global attack volume. Europe followed with 29 percent of attacks. This geographic distribution reflects the financial motivations of RaaS groups, which prioritize regions with high-GDP organizations capable of paying substantial ransoms. However, researchers also noted a rise in attacks targeting South America and the Asia-Pacific region, suggesting that ransomware groups are diversifying their target profiles to avoid the intense scrutiny of Western law enforcement.
Official Responses and Tactical Implications
The resurgence of these groups has prompted renewed warnings from cybersecurity agencies worldwide. The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have continued to emphasize that paying ransoms does not guarantee data recovery and may embolden further attacks. Official guidance remains focused on the "Shift Left" strategy—implementing robust preventative measures such as multi-factor authentication (MFA), offline backups, and regular patch management to stop attacks before the encryption phase begins.
The emergence of BlackBasta and the resurgence of Hive indicate a tactical shift toward "double extortion" as a standard operating procedure. In these scenarios, attackers not only encrypt the victim’s data but also exfiltrate sensitive information, threatening to leak it on public "shame sites" if the ransom is not paid. This strategy provides the criminals with additional leverage, particularly against organizations that might have robust backup systems and could otherwise ignore the encryption threat.
Analysis of Future Trends
As the industry moves into the latter half of 2022, the trend lines suggest that the ransomware threat will continue to intensify. The professionalization of Lockbit 3.0 has set a new benchmark for RaaS operations, likely forcing other groups to adopt similar "corporate" features to remain competitive in the criminal marketplace. The fragmentation of Conti into smaller, more agile cells like BlackBasta makes the threat more difficult for law enforcement to track and dismantle, as there is no longer a single point of failure for the entire ecosystem.
The NCC Group report concludes with a warning that the figures seen in July are likely a precursor to a more active August. As the "Conti diaspora" fully integrates into their new roles and the Lockbit 3.0 platform attracts more affiliates, the volume of attacks could soon return to the record levels seen earlier in the year.
The current landscape serves as a reminder that the ransomware ecosystem is a highly adaptable market. When one major player falls, the vacuum is quickly filled by leaner, more technologically advanced entities. For organizations, this means that the "threat pulse" is no longer a seasonal concern but a constant pressure. The rise of Lockbit, Hive, and BlackBasta underscores the necessity of a proactive, intelligence-led defense strategy that anticipates the evolution of these persistent threat actors.







