A new report, from financial and risk advisory firm Kroll has found that ansomware groups adjusted strategies in Q4 2023, witnessing declines in major ransomware-as-a-service (RaaS) operations.
Yet, the report, called Cyber Threat Landscape Report: Threat Actors Breach the Outer Limits noted that challenges persisted, particularly, the sustained focus on the professional services industry is a cause for concern. Although phishing attempts dropped, the evolution of tactics, like QR codes, and the prevalence of business email compromise (BEC) continued.
Q4 saw a substantial focus on the professional services industry (24% of attacks compared to 16% in 2022), marking a persistent trend from 2023. While the health care sector also faced increased ransomware activity (13%, up from 9%), manufacturing saw a small drop (12% in 2023 compared to 13% in 2022).
Larger RaaS operations like LockBit and BlackCat experienced declines in activity, accounting for 38% of ransomware activity in Q1 2023 but dropping to 22% by the end of year, clearing the way for the rise of ransomware such as Akira and Play, which made up 16% and 11% of ransomware attacks in Q4 2023.
To counter ransomware threats, Kroll suggests enforcing MFA for VPN access, prioritising VPN appliance vulnerability patching, implementing risk profiling, enabling role-based access control, and adopting regular attack simulations.
Recommended reading
- Ransomware Attacks Up 73% in January 2024 Year-on-Year
- NCSC Warns Ransomware Threat to Rise with AI
- New Threat Actors Contribute to Big Rise in Ransomware Attacks
Q4’s challenges, particularly the rise in external remote services as a ransomware vector, indicate a demanding year ahead. The quarter showcased a blend of positive and negative trends, emphasising the need for organisations to adopt a consistent security approach and collaborate with trusted security partners.
The increased usage of external remote services by ransomware groups and the surge in infostealer malware underscore the importance of proactive cybersecurity measures. According to the report, organisations acting now are better positioned to achieve the required cyber maturity to navigate threats in 2024.





