Threat Trend Report on Ransomware – Statistics and Major Issues in March 2024

Threat Trend Report  on Ransomware – Statistics and Major Issues in March 2024

Purpose and Scope

 

This report provides statistics on the number of new ransomware samples, targeted systems, and targeted businesses in March 2024, as well as notable ransomware issues in Korea and other countries. Other major issues and statistics for ransomware that are not mentioned in the report can be found by searching for the following keywords or via the Statistics menu at AhnLab Threat Intelligence Platform (hereinafter “ATIP”). 

 

Disclaimer: The number of ransomware samples and targeted systems are based on the detection names designated by AhnLab, and the statistics on targeted businesses are based on the time the information on the ransomware group’s Dedicated Leak Sites (DLS, identical to ransomware PR sites or PR pages) was collected by the ATIP infrastructure.

 

Major Statistics

 

1) Data Sources and Collection Methods
 

ATIP uses its internal infrastructure to monitor and analyze the following ransomware information. 

  • List of malicious files and behaviors detected and collected by AhnLab Smart Defense (ASD)
  • List of targeted businesses posted on ransomware groups’ DLS

 

The number of new ransomware samples and statistics on targeted systems were calculated based on the detection names designated by AhnLab. They were also limited to cases where the detected files and behaviors were diagnosed under the category of “Ransomware/” or “Ransom/”. 

  • Ransomware/Win.Magniber: Example file detection name
  • Ransom/MDP.Magniber: Example behavior detection name

 

The detection names acquired at the time of detection may not allow for the identification of ransomware types (e.g. Generic, Agent, Edit, Decoy, and others), and some cases may be excluded from the ransomware statistics or be counted as a different ransomware type due to changed detection names after detection or a failed detection.

 The statistics on targeted businesses are the values that have been organized based on the data accumulated through regular monitoring of ransomware groups’ DLS, where the groups reveal the targeted businesses. If the DLS page was inaccessible or the collection happened late, then the data may have been excluded from the statistics or have been considered to be collected at a time different from the exact date the victim was revealed.

 Therefore, this report should be used as a reference to check the general trends of ransomware samples and targeted systems and to see which ransomware groups are actively engaged in attacks through the statistics on targeted businesses to gain a general understanding of trends.

 

2) Overall Ransomware Statistics

 

The total number of new ransomware samples collected during the past six months is as follows


Figure 1. Number of new ransomware samples

 

The trend of increase in new samples decelerated in March. This is due to the files that were detected under the aliases Babuk and Conti in January and February were removed from the top of the rank.

About 2,000 samples of the above two types were collected in January and February, but these two did not make the top of the list and 631 new samples were found instead. This report will discuss malware comprising the March new sample counts in more detail from “3. New Samples by Ransomware.” 

The table below shows the total numbers after removing redundant data of ransomware files used in targeted systems and infection. (The term “targeted systems” is used for your convenience, but more precisely, it should be understood as systems exposed to infection with detected ransomware files or behaviors.)

 
 


Figure 2. Systems and files affected by ransomware

 

While there was a small decrease in affected systems in March in comparison to those in February, the numbers were still high.

Attempts at Magniber infection have been increasing since early December 2023 and steadily showed high numbers all throughout Q1 2024. The number of systems infected by Magniber in February was about 57 on average per day, with the figure for March being almost the same at 56 per day. See “Figure 6. Daily number of targeted systems by ransomware (March 2024)” for specific figures. 

The total number of ransomware behavior detection (MDP)-based targeted systems and blocked report cases are as follows.

 


Figure 3. Affected systems where ransomware behavior was detected and reports

 

Statistics on systems where behavior detection occurred showed lower numbers than the previous month, being similar overall to the figures of January 2024. There were no Magniber ransomware file variants and the distribution of the malware has not resumed.

 

3) New Samples by Ransomware
 

Below is the statistics showing the 631 new samples that were discovered in March organized by ransomware type. Only 20 ransomware with the most samples are shown.


Figure 4. Number of new samples per ransomware (March 2024)

 

Compared to February, the number of new samples collected in March decreased significantly. As mentioned before, this reduction was due to about 2,000 files detected as Babuk and Conti having disappeared from the top ranking. 

GandCrab, which ranked first in the figure, is a ransomware that had actively been distributed from early 2018 to Q2 2019. It caused immense harm worldwide with its wide range of variants. While GandCrab disguised as resumes and HWP files targeting Korean users, it has since disappeared: its activities are logged only until 2019 and even the developer expressed their intent to cease development. The GandCrab ransomware samples collected by the AhnLab infrastructure in March were all files created and distributed between February and June 2018. No variants have been made, and distribution has not resumed. 

In addition, samples of Magniber ransomware, which always ranked among the top, were discovered to be those of past types distributed between August 2021 and June 2023.

 

SHA2

10a3fc2cdb4f7f7bb7fd4af1bce19e9c9cf064dff9929e18e0cdc53879d90ebe
2b9afcb78e02972fb7ce137c0e3729eae9068ec739c21205ee446ae5ff2f809a
2e62a782c84149953dd216d96fec8e0f4d4b568525bbaa0574b1aad2530d28e0
323f82b2fad350cc1ff7d1a2473d4b0a45aca6d4992da9925847bb5d9b6c16e6
3581f1c9ee74f83d3d476aa5a947a040d9f2613a836232180c195f678b64dee6