Lockbit dominates the summer ransomware landscape as Conti offshoots drive a resurgence in global cyberattacks

The global cybersecurity landscape has experienced a volatile shift over the summer months, characterized by a marked resurgence in ransomware-as-a-service (RaaS) activity. According to the latest monthly threat intelligence report from the NCC Group, the number of successful ransomware campaigns surged by 47 percent in July compared to the preceding month. This sudden uptick in activity, which saw 198 reported incidents, signals that the temporary lull observed in the late spring may have been a period of tactical regrouping rather than a permanent decline in criminal operational capacity.
At the center of this aggressive landscape is the Lockbit group, which has cemented its status as the most prolific threat actor currently operating. By actively monitoring leak sites and scraping victim data, researchers identified that Lockbit was responsible for 62 confirmed attacks in July alone. This figure represents a significant escalation, marking a ten-attack increase from June and cementing a lead that places the group well ahead of its competitors. With the introduction of Lockbit 3.0, the gang has demonstrated both technical evolution and operational persistence, forcing security professionals to re-evaluate their defensive postures.
The Evolution of the Threat Landscape
The recent surge in ransomware is not merely a random spike but appears to be a direct consequence of structural changes within the cybercriminal underworld. For much of the early part of the year, the ransomware ecosystem was dominated by a few massive, monolithic entities. However, the landscape shifted dramatically following a concerted campaign by international law enforcement and intelligence agencies to dismantle the infrastructure of the Conti group.
Conti, once the undisputed leader of the global ransomware trade, became the target of intense scrutiny following the invasion of Ukraine and subsequent disclosures regarding its internal operations. In May, the United States Department of State issued a formal offer of up to $15 million for information leading to the identification and localization of key members of the Conti leadership. This move, coupled with internal organizational fractures, effectively neutralized the Conti brand.
However, the threat did not dissipate; it fragmented. The NCC Group report identifies that the void left by Conti has been filled by two emerging groups: Hiveleaks and BlackBasta. The rise of these entities has been nothing short of meteoric. Hiveleaks recorded 27 attacks in July, a staggering 440 percent increase from its June activity. Simultaneously, BlackBasta accounted for 24 attacks, a 50 percent month-over-month increase. These groups, while technically distinct in name, are widely considered to be the direct descendants of the Conti infrastructure, utilizing the same human capital, technical expertise, and operational playbooks that once made Conti the world’s most dangerous cybercrime enterprise.
Chronology of a Resurgence
To understand the current volatility, one must examine the timeline of the 2022 ransomware cycle. The year began with a robust cadence of activity, peaking in March and April, with each month seeing nearly 300 successful ransomware campaigns. During this period, the threat landscape was characterized by a high volume of attacks against mid-to-large-sized enterprises across the healthcare, manufacturing, and technology sectors.
The subsequent decline in May and June—where the total number of attacks dropped significantly—was initially hailed as a success for international law enforcement. It was during this period that the pressure on the Conti syndicate reached a boiling point. The structural disintegration of the group forced its former affiliates to pivot. Some moved to existing RaaS platforms like Lockbit, while others, as evidenced by the rise of BlackBasta, chose to strike out on their own, rebranding their operations to evade detection and distance themselves from the heat of international sanctions.
By July, these new, smaller, and more agile entities had finished their restructuring phase. The 198 attacks recorded in July represent the first major sign of a consolidated comeback. While this total remains lower than the highs of early spring, the speed of the rebound suggests that the underlying infrastructure for cybercrime—including access brokers, exploit kits, and exfiltration sites—has remained resilient despite the disruption of top-tier leadership.
Supporting Data and Sector Vulnerabilities
The data provided by the NCC Group underscores a grim reality for organizations: no sector is immune, though some remain primary targets. In July, the industrial and technology sectors bore the brunt of the attacks. The transition toward RaaS models has lowered the barrier to entry for cybercriminals, allowing even those with limited technical proficiency to execute high-impact attacks by purchasing access from "Initial Access Brokers."
Lockbit 3.0, in particular, has introduced features that make it an attractive platform for affiliates. These include more sophisticated encryption modules and a more robust interface for managing victim communications and ransom negotiations. By operating as a platform that incentivizes third-party hackers, Lockbit ensures a steady stream of revenue, allowing the core developers to focus on evasion tactics and payload refinement.
The following data points highlight the intensity of the current threat:
- July Total: 198 successful campaigns.
- Monthly Growth: 47 percent increase over June.
- Lockbit Dominance: 62 attacks (more than double the second and third-ranked groups combined).
- Conti Offshoot Velocity: A 440 percent surge for Hiveleaks and a 50 percent surge for BlackBasta within a single month.
These numbers illustrate that ransomware is moving toward a more decentralized model. Instead of relying on one massive, vulnerable group like Conti, the ecosystem has shifted to a "hydra" approach, where the destruction of one entity simply leads to the emergence of two or more smaller, more difficult-to-track groups.
The Implications for Global Cybersecurity
The broader implication of this shift is that the traditional "whack-a-mole" strategy of law enforcement—focused on taking down individual servers or identifying high-level leaders—may be losing its effectiveness against a more decentralized threat actor network. While international rewards and sanctions remain vital tools for delegitimizing these criminal operations, they are unlikely to stop the flow of ransomware in the short term.
Cybersecurity experts argue that organizations must transition from a reactive posture—which relies on waiting for signs of an infection—to a proactive, "assume breach" mindset. The success of Lockbit and the Conti offshoots relies heavily on the exploitation of known vulnerabilities and the use of compromised credentials. By implementing multi-factor authentication (MFA), enforcing strict patch management cycles, and utilizing endpoint detection and response (EDR) tools, companies can significantly raise the cost of an attack for these groups.
Furthermore, the rise of groups like BlackBasta, which often targets critical infrastructure and service providers, suggests that the focus of ransomware gangs is moving toward entities with the least tolerance for downtime. These groups understand that if they can paralyze a company’s operations, the pressure to pay the ransom increases exponentially.
Looking Toward the Future
As the industry moves into the latter half of the year, researchers expect the current trend of increasing attack volumes to continue. The professionalization of RaaS, coupled with the rapid integration of former Conti affiliates into new, leaner operations, creates a highly favorable environment for cybercriminals.
The NCC Group authors have warned that the transition period for these groups is largely complete. With the infrastructure established and the "rebranding" phase behind them, Hiveleaks, BlackBasta, and the dominant Lockbit organization are likely to scale their operations further. For the global business community, this means that the threat is not just returning to its previous levels; it is evolving into a more persistent and pervasive danger.
The coming months will likely see an intensification of the arms race between security vendors and these ransomware syndicates. Organizations that fail to prioritize threat intelligence and robust incident response planning are increasingly likely to find themselves on the front lines of this digital conflict. The resurgence in July serves as a definitive wake-up call: the ransomware threat has not been defeated; it has merely changed its face. In the current climate, maintaining visibility into the activities of these groups is not just an optional security measure—it is a core requirement for survival in an increasingly hostile digital landscape.







