Ransomware resurgence surges as Lockbit and Conti offshoots dominate the global threat landscape

The global cybersecurity landscape is grappling with a significant resurgence in ransomware activity, as data from the NCC Group’s latest Monthly Threat Pulse indicates that the reprieve observed earlier this spring has been short-lived. Following a period of relative quiet, the velocity of attacks accelerated sharply in July, with 198 confirmed campaigns reported—a 47 percent increase over the figures recorded in June. At the center of this renewed offensive is the Lockbit ransomware group, which has cemented its status as the most prolific threat actor in the ecosystem, while the fragmented remnants of the notorious Conti syndicate have begun to reassert their influence through new, agile iterations.
The current escalation serves as a sobering reminder of the cyclical and adaptive nature of cybercriminal organizations. While the total number of successful compromises remains below the record-breaking peaks of March and April, which saw nearly 300 campaigns each, the rapid rise in July suggests that threat actors have successfully navigated internal restructuring and are once again scaling their operations with renewed vigor.
The Dominance of Lockbit 3.0
Lockbit has distinguished itself as the undisputed leader in the ransomware-as-a-service (RaaS) market. According to threat intelligence gathered by monitoring leak sites and scraping victim disclosures, Lockbit was responsible for 62 successful attacks in July alone. This figure represents a ten-attack increase from the previous month and positions the group as a dominant force, responsible for more than twice as many incidents as its two closest competitors combined.
Security analysts have noted that the iteration known as "Lockbit 3.0" demonstrates a high degree of operational maturity. By employing an efficient RaaS model, the group allows affiliates to leverage its proprietary infrastructure in exchange for a percentage of the ransom proceeds. This decentralized approach makes the group exceptionally difficult to disrupt, as the core developers provide the technical payload while external affiliates execute the initial entry and lateral movement within target networks. The NCC Group report highlights that Lockbit’s sustained presence is a critical concern for organizations across all sectors, as their tactics, techniques, and procedures (TTPs) continue to evolve, making traditional signature-based detection increasingly ineffective.
The Shadow of Conti and the Rise of Offshoots
The resurgence of ransomware is not merely the result of Lockbit’s expansion; it is also intrinsically linked to the reorganization of the Conti ransomware group. Once considered the most feared cybercriminal syndicate in the world, Conti faced intense pressure following the Russian invasion of Ukraine and subsequent international law enforcement scrutiny. In May, the United States Department of State announced a reward of up to $15 million for information leading to the identification or location of key members of the Conti gang, a move that effectively forced the group to dissolve its centralized structure to avoid capture.
However, the threat posed by Conti has not dissipated; it has simply evolved. Researchers have identified Hiveleaks and BlackBasta as two primary entities that have emerged from the wake of Conti’s dissolution. These groups are functioning as the structural successors to the original syndicate. Hiveleaks has seen a staggering 440 percent increase in activity since June, while BlackBasta has experienced a 50 percent growth, accounting for 27 and 24 attacks in July, respectively.
The rapid rise of these two groups suggests that the human capital and technical expertise formerly concentrated within Conti have been redistributed. By operating under different branding and potentially more fragmented leadership, these actors are attempting to minimize the risk of being targeted by international intelligence agencies while maintaining the operational capacity to execute high-stakes extortion campaigns.
Chronology of the 2022 Ransomware Climate
To understand the current volatility, it is necessary to examine the trajectory of ransomware activity throughout the first half of 2022:
- Q1 2022 (March–April): The ransomware threat environment reached a high-water mark, with monthly campaign counts nearing 300. This period saw heavy reliance on established RaaS models, including the original Conti infrastructure.
- May 2022: A critical inflection point occurred. The United States government formalized its offensive against Conti, issuing the multi-million dollar reward bounty. Simultaneously, internal leaks within Conti, which exposed sensitive source code and communications, severely hampered the group’s operational security.
- June 2022: The immediate aftermath of the government crackdown led to a noticeable dip in total ransomware incidents as the group underwent a period of transition and internal restructuring.
- July 2022: The emergence of specialized offshoots and the aggressive expansion of Lockbit 3.0 signaled the end of the lull, with a 47 percent month-over-month surge in successful attacks.
Structural Changes and Industry Implications
The shift from a centralized, monolithic group like Conti to more fragmented entities like Hiveleaks and BlackBasta represents a strategic pivot in the cybercriminal economy. By operating in smaller, more agile cells, these groups can rotate infrastructure, switch payloads, and pivot targets with greater speed than larger organizations.
This restructuring has significant implications for enterprise security teams. When a major syndicate like Conti breaks apart, the resulting offshoots often carry over the sophisticated TTPs, internal knowledge, and illicit access channels developed by their predecessor. This "legacy expertise" allows them to become effective threat actors almost immediately upon formation.
Furthermore, the professionalization of the RaaS model means that the barrier to entry for cybercrime remains low. An affiliate with minimal technical training can purchase access to sophisticated ransomware payloads, effectively outsourcing the complexity of encryption, negotiation, and data exfiltration to the RaaS provider. As Lockbit continues to set the standard for these services, other groups are being forced to improve their own performance to remain competitive, creating a "race to the top" in terms of criminal efficiency.
Broader Impact and Risk Mitigation
The economic impact of this resurgence is profound. Ransomware is no longer merely a technical issue for IT departments; it is a systemic financial and operational risk. The average downtime associated with a ransomware attack—caused by the need to restore from backups, investigate the scope of the breach, and mitigate ongoing vulnerabilities—can cost organizations millions of dollars in lost productivity and remediation expenses.
In response to these trends, security experts emphasize a multi-layered defense strategy:
- Immutable Backups: Ensuring that critical data is backed up to an offline or immutable environment is the single most effective defense against the need to pay a ransom.
- Zero Trust Architecture: By strictly verifying every request for access to corporate resources, organizations can limit the ability of attackers to move laterally through the network if they do gain an initial foothold.
- Threat Intelligence Integration: Organizations must move beyond static security controls and integrate real-time intelligence feeds to identify indicators of compromise (IoCs) associated with groups like Lockbit, BlackBasta, and Hiveleaks.
- Employee Vigilance: Because many ransomware attacks begin with phishing or the exploitation of stolen credentials, robust security awareness training remains a fundamental requirement for the modern workforce.
The Future Outlook
As the cyber threat landscape moves into the latter half of the year, researchers anticipate that the figures reported in July are likely to serve as a baseline rather than a peak. The successful consolidation of Conti’s remnants into new, aggressive groups suggests that the threat landscape will remain highly active.
The persistence of the RaaS model ensures that there will be a steady supply of motivated affiliates looking to monetize their access to corporate networks. As long as the financial returns from ransomware remain high and the risks of detection for the core developers remain relatively low, the cycle of extortion and remediation is unlikely to break.
For organizations, the message from the latest NCC Group findings is clear: the period of relative stability in early summer was an anomaly rather than a trend. With Lockbit 3.0 maintaining its aggressive pace and new, rebranded Conti-affiliated groups gaining traction, the need for heightened vigilance and proactive security measures has never been greater. Companies that fail to adapt their security posture to the shifting landscape of these evolving criminal syndicates remain highly vulnerable to the next wave of coordinated, high-impact ransomware campaigns.







