Site navigation

‘Big Game’ Ransomware Tactics Drives Spike in Attacks

Staff Writer

,

ransomware attack tactics
A new report from Malwarebytes shows a record number of ransomware attacks, with ‘big game’ tactics leading to larger payouts and a rise in service-sector targets.

The number of known attacks increased 13% last year, with over six hundred attacks recorded in November 2024, more than any other month over the last two years, according to the latest figures from Malwarebytes.

The security providers State of Malware 2025 report claims that last year saw the emergence of ‘big game’ ransomware attacks, with entire organisations being targeted rather than individual computers in an effort to extort bigger payouts than ever before.

To a large extent, the study argues, this new tactic worked. Last year, the Dark Angels group received a record-breaking $75 million (£58 million) ransomware payment, while ransomware gangs combined raked in $459.8 million (£353.24m) in the first half of 2024. 

The data shows that American companies were the primary focus for these big game attacks, with half of all ransomware incidents recorded in the US (51%), an especially high figure when compared to attacks suffered by firms in the UK (5%), Canada (5%), Germany (3%), and France (2%).  

According to Malwarebytes, firms in the services industry were among the most vulnerable to ransomware attacks, accounting for almost a fifth of those publicly known (19%), however threat actors also heavily targeted those in manufacturing (13%), construction (9%), and IT services (8%).

The report notes that the spike in attacks against the services and manufacturing sectors is evidence of ransomware gangs finding more targets in areas of the economy that are less obviously dependent on computers.

That change in tactic could be in response to both improving cybersecurity defences, and a growing reluctance of victims to pay their attackers, with Malwarebytes reporting that it has observed ransomware gangs adopting three new methods to increase the success of their attacks.

In the last twelve months, the firm’s specialist malware removal team saw threat actors more frequently begin attacks in the early hours – mostly between 1am and 5am – in the hope that fewer IT staff will be available, and are taking less time to complete their assaults than ever before, with the entire ransomware attack chain now taking hours opposed to weeks.

Malwarebytes data also shows that more ransomware gangs are now using ‘Living Off the Land’ techniques, leveraging legitimate software and admin tools for malicious purposes, with recent incidents from major gangs such as LockBit, Akira, and Medusa revealing ransomware attack chains are increasingly composed of LOTL techniques.


Recommended reading


Remote access tools have emerged as among the most popular means for attackers to gain access, accounting for an entry point in 58% of the ransomware cases dealt with by Malwarebytes, and now higher than more traditional entry points, such as phishing (25%).

“This “democratisation” of ransomware is unwelcome news. Intelligence suggests that there are many more potential targets for ransomware than attacks,” reads the report.

“A lower barrier to entry makes ransomware an option for more criminal gangs, will fuel an increase in attacks, and could spur innovation and experimentation in the tactics that are used.”

DIGIT Staff Writer Robot

Staff Writer

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data