Summary Points
- Ransomware incidents rose by 3% in Q2, with notable activity from groups like Qilin, The Gentlemen, and DragonForce, primarily targeting industrial sectors and North America.
- Supply chain attacks and targeted exploitation of software dependencies, development tools, and VPN vulnerabilities are increasing, amplifying systemic risk across organizations.
- Threat actors are employing more sophisticated tactics, leveraging compromised software workflows and exploiting high-critic vulnerabilities, necessitating continuous cybersecurity resilience and monitoring.
Threat, Techniques, and Targets
NCC Group reported a rise in ransomware attacks worldwide in the second quarter. There were 2,229 incidents, which is 3% higher than the first quarter. Several established ransomware groups remained active, with Qilin being the most active for five straight quarters. Qilin caused 301 attacks, making up 14% of all attacks. However, this was 11% fewer than the previous quarter. Other active groups include The Gentlemen and DragonForce. Attacks linked to these groups increased by 60% from the first to second quarter. Akira also launched 127 attacks, a drop from the last quarter. New threats like KryBit have entered the top ten most active groups.
Most attacks targeted industrial companies, which experienced 30% of all incidents. Consumer Discretionary and Information Technology sectors also saw many attacks. Geographically, North America experienced the highest number of attacks, with 44% of the global total in Q2. Europe was second, followed by Asia. The attacks mainly focused on software development ecosystems. Threat groups are increasingly targeting supply chain systems, including software and development tools. Attackers also targeted virtual private networks (VPNs) and internet-facing devices, exploiting vulnerabilities to access organizations’ internal networks.
Impact, Implications, and Guidance
The rise in supply chain and network device attacks increases the risk of operational disruption, financial loss, and damage to reputation. Attackers using compromised software dependencies can spread malware across many organizations quickly. Threat actors continue to attack VPNs and vulnerable internet-facing devices, which can give them unauthorized access. Many vulnerabilities in VPN products are rated high or critical, making these targets especially dangerous.
Organizations should improve their monitoring and security resilience continuously. They need to stay updated about vulnerabilities and security alerts. Security policies should focus on protecting supply chains and network devices. For specific remediation advice and to stay current with vulnerabilities, organizations should consult their software vendors or trusted authorities. This will help them prevent and respond effectively to such threats.
Continue Your Tech Journey
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
