Lockbit Emerges as Summer’s Dominant Ransomware Force Amidst the Fragmented Resurgence of Conti Offshoots

The global cybersecurity landscape is witnessing a volatile transformation as ransomware activity rebounds from a mid-spring lull. Data compiled by the NCC Group indicates that the total number of successful ransomware campaigns rose to 198 in July, representing a 47 percent increase compared to the previous month. While this resurgence remains below the peak levels observed in March and April—where nearly 300 campaigns were recorded—the shifting composition of the threat landscape suggests that ransomware-as-a-service (RaaS) operations are successfully adapting to international law enforcement pressure. At the center of this storm is Lockbit 3.0, which has solidified its position as the most prolific threat actor, while the remnants of the once-dominant Conti group have reorganized into agile, highly active offshoots.
The Ascendancy of Lockbit 3.0
Lockbit 3.0 has established a significant operational lead over its competitors, demonstrating a level of technical sophistication and recruitment capability that has outpaced the broader market. According to threat intelligence gathered by monitoring leak sites and scraping victim disclosures, Lockbit was responsible for 62 confirmed attacks in July. This figure marks a steady climb from 52 attacks in June, cementing the group’s status as the primary threat to enterprise security.
The efficiency of the Lockbit operation is underscored by the gap between its output and that of its closest rivals. In July, Lockbit’s volume was more than twice the combined total of the second and third most active groups. Security analysts emphasize that Lockbit’s move to a "3.0" iteration has not only introduced new encryption techniques but has also expanded its bug bounty program and affiliate incentive structures, attracting a wider base of cybercriminals looking for a stable and profitable RaaS platform. Organizations across all sectors are now being advised to treat Lockbit as an omnipresent risk, necessitating proactive threat hunting and robust incident response planning.
The Fragmentation of Conti: Hiveleaks and BlackBasta
The resurgence in total ransomware volume is largely attributed to the successful rebranding and restructuring of former Conti affiliates. Earlier this year, the notorious Conti group—previously responsible for a massive share of global ransomware revenue—faced significant internal friction following a public fallout over its political allegiances and a subsequent leak of its internal communications. This volatility was compounded in May by the United States Department of State, which announced a reward of up to $15 million for information leading to the identification or conviction of key members of the Conti syndicate.
The pressure proved effective in forcing the dissolution of the unified Conti brand. However, the intelligence gathered by the NCC Group reveals that the underlying infrastructure and human capital did not vanish; rather, they shifted into new entities. Hiveleaks and BlackBasta have emerged as the primary successors to the Conti legacy.
Hiveleaks saw a staggering 440 percent increase in activity between June and July, accounting for 27 reported attacks. Simultaneously, BlackBasta recorded 24 attacks, a 50 percent increase over the same period. These two groups serve as a case study in the resilience of cybercriminal organizations. Hiveleaks appears to be operating as a direct affiliate successor, while BlackBasta has emerged as a distinct, aggressive strain that utilizes sophisticated lateral movement tactics often associated with the former Conti developers. The rapid rise of these groups suggests that the threat actors formerly behind Conti have successfully integrated into new operational models, allowing them to bypass the sanctions and investigative scrutiny that crippled their previous organization.
Chronology of the 2022 Ransomware Fluctuation
The current state of the ransomware market follows a clear timeline of geopolitical and law enforcement intervention.
- Q1 2022: Ransomware activity reached an early-year peak, with March and April recording nearly 300 campaigns per month.
- May 2022: The United States government issued a formal bounty of $15 million for information on Conti leadership. This period saw a noticeable dip in total ransomware volume as major syndicates underwent structural changes.
- June 2022: Initial post-Conti reorganization began to take hold. While total volume remained lower than the spring, smaller, more agile groups began to gain market share.
- July 2022: The resurgence solidified. NCC Group data confirmed 198 successful campaigns, with Lockbit 3.0, Hiveleaks, and BlackBasta emerging as the dominant players in a fractured ecosystem.
Analysis of the RaaS Business Model
The resilience of the RaaS model is rooted in its modular nature. By separating the developers—who build and maintain the encryption software—from the affiliates—who execute the breaches and negotiate the ransoms—these groups can weather individual arrests or operational disruptions. When a major group like Conti faces intense scrutiny, the developers simply move to a new brand, while the affiliates migrate their operations to the most stable and profitable platform currently available.
Lockbit’s success is a testament to this model’s durability. By incentivizing affiliates through higher payouts and a more user-friendly interface, Lockbit has effectively absorbed the talent pool previously associated with less stable groups. This centralization of criminal expertise creates a "winner-take-all" dynamic where the largest RaaS provider gains access to better tools, more data, and a larger network of initial access brokers.
Industry and Governmental Implications
The shift toward smaller, decentralized ransomware groups creates significant challenges for law enforcement and private security firms. Tracking a single, large organization like Conti allowed for concentrated investigative efforts. Tracking dozens of smaller, rapidly evolving groups like BlackBasta and Hiveleaks requires a significantly higher investment in cross-jurisdictional intelligence sharing.
Furthermore, the surge in July has led many cybersecurity experts to warn that the "lull" observed in May and June was merely a transition phase rather than a permanent reduction in the threat level. Industry reports suggest that as these new entities stabilize their operational workflows, the frequency of attacks is likely to continue rising through the remainder of the third quarter.
For organizations, the primary implication is the need for a shift in defensive strategy. Traditional perimeter-based security is increasingly insufficient against groups that utilize double-extortion tactics—where data is exfiltrated before encryption—and exploit human vulnerabilities through sophisticated social engineering. Security posture must now focus on behavioral analytics, rapid detection of lateral movement, and the implementation of immutable backups to render the threat of data destruction less effective.
Broader Cybersecurity Outlook
As the threat landscape moves into the latter half of the year, the consensus among researchers is one of cautious concern. The transformation of the Conti syndicate into multiple, smaller, and highly active groups demonstrates that law enforcement interventions, while disruptive, are often met with rapid organizational evolution rather than dissolution.
The dominance of Lockbit 3.0 also indicates that the market for ransomware is maturing, with top-tier players investing in professionalized software development and recruitment. The increased volume of attacks in July serves as a clear indicator that the ransomware economy is not merely recovering, but evolving into a more resilient and distributed threat. Organizations must prepare for a future where ransomware is not a static threat to be "solved," but a persistent, dynamic operational risk that requires continuous vigilance, updated threat intelligence, and a proactive approach to data integrity. As the authors of the NCC Group report noted, the ability of these groups to filter back into the landscape under new identities is a trend that is unlikely to abate, suggesting that the figures for August and beyond may continue on their upward trajectory.






