Ransomware and Cyber Extortion in Q4 2024
ID: 85b59a8b-d828-5ae2-8a3d-f60971358894
STIX ID: report--85b59a8b-d828-5ae2-8a3d-f60971358894
Feed Name: ReliaQuest Blog
Q4 2024 ransomware analysis: attacks peaked in December with record victim counts and nearly 100 active ransomware groups; notable activity includes Akira exploiting CVE-2024-40766 for SonicOS access, RansomHub powered by Scattered Spider tactics (phishing, SIM-swapping), and rapid growth of BlackLock. The report details sector and geographic targeting (US, manufacturing, PSTS), patterns of domain impersonation used for credential harvesting, rising ransom payments, and offers mitigation guidance (patch VPN appliances, phishing-resistant MFA, immutable backups, detections and automated playbooks).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
