New research from Searchlight Cyber, the cybersecurity and dark web intelligence specialist, has found a worrying increase in the number of active ransomware groups.
According to Searchlight’s most recent report, there were 56% more ransomware groups conducting attacks around the globe compared to the same period last year.
The report takes a deep dive into the most active ransomware groups in 2024, creating a “league table” of the most prolific and established players.
At the top of the list is the notorious Lockbit group, considered the largest ransomware group by law enforcement, with 434 recorded victims. That number is down from 525 victims in H1 2023, in part thanks to the disruption of Operation Cronos, which saw the UK’s National Crime Agency and its partners take control of LockBit’s services, compromising their enterprise.
Among the other top five attackers noted by Searchlight were the Play, Blackbasta, and 8base groups, with a combined 473 victims.
Notably, the other entry at number three on the list is the Ransomhub group, which according to the study was previously unranked and emerged only in February 2024, but has quickly become one of the most active ransomware-as-a-service (RaaS) operations tracked.
As well as Ransomhub, other new groups the report warns about are Darkvault, APT73, and Quilong, all emerging between February and April this year. While Darkvault and Quilong are suspected of being RaaS groups, putting ransomware code up for sale, there is no evidence APT73 is, though the report notes this group is unusual in that it has both a dark-web and clear-web site.
Luke Donovan, head of threat intelligence at Searchlight Cyber, said: “With over 70 active ransomware groups now in operation, the ransomware landscape is becoming more complex for cybersecurity professionals to navigate. The diversification we’re witnessing means that smaller, lesser-known groups can emerge rapidly and execute highly targeted attacks.
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Ransomware Crisis Escalating Globally, New Report Shows
- What Were the Key Ransomware Trends in July?
“This report underscores the need for organizations to continuously monitor the ransomware ecosystem, identify the groups that pose the greatest risk to them, and use threat intelligence to inform their defensive strategies.”
Another study released earlier this month found that 83% of businesses had suffered ransomware attacks last year, with 46% facing four or more attacks, while current trends suggesting that 2024 will be the highest-grossing year for ransomware payments yet, with a record $459.8 million (£353.24m) already raked in over the first six months of the year.





