惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 【当耐特】
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
博客园 - Franky
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
月光博客
月光博客
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
Microsoft Security Blog
Microsoft Security Blog
Last Week in AI
Last Week in AI
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
爱范儿
爱范儿
J
Java Code Geeks
博客园 - 叶小钗
Engineering at Meta
Engineering at Meta
阮一峰的网络日志
阮一峰的网络日志

www.infosecurity-magazine.com

Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns Eight in 10 UK Manufacturers Hit by Cyber Incident in a Year
Just Three Ransomware Gangs Accounted for 40% of Attacks ...
Danny Palmer · 2026-04-10 · via www.infosecurity-magazine.com

Just three ransomware groups were responsible for almost half of all ransomware attacks during the last month, analysis of reported incidents has revealed.

According to cybersecurity analysts at Check Point, a total of 672 ransomware incidents were reported during March 2026, representing an increase in attacks compared with the previous month.

The figures, released on April 9, detailed how three ransomware operations dominated the attack landscape, as they accounted for 40% of incidents.

Qilin ransomware group alone was responsible for 20% of ransomware attacks. The ransomware-as-a-service (RaaS) operation has been active since 2022 and remains a prominent cyber threat.

Since early 2025, Qilin has significantly expanded affiliate recruitment and victim disclosures, which last year included a disruptive ransomware attack on global brewing giant Asahi.

During the same period, Akira ransomware accounted for 12% of all ransomware attacks. Akira has remained a threat since it first appeared in 2023 and the ransomware group has extorted hundreds of millions of dollars in ransom payments.

The group targets Windows, Linux, and ESXi systems and has shown an increased preference for targeting organizations in the business services and industrial manufacturing sectors.

Akira has continued to evolve its capabilities, researchers recently disclosed how the ransomware is now capable of completing all stages of an attack in under one hour from the initial compromise.

Dragonforce RaaS was responsible for 8% of ransomware attacks during March. According to Check Point, Dragonforce’s activity accelerated, something which researchers attributed to absorption of displaced RansomHub affiliates and a spike in social engineering campaigns.

Half of Ransomware Attacks Target the US

While the top three malicious actors accounted for 40% of incidents, a total of 47 different ransomware groups publicly impacted organizations worldwide during the period. Organizations in the United States accounted for just over half (52%) of victims.

“Attackers continue refining precision, timing, and targeting, exploiting seasonal cycles, emerging technologies, and operational blind spots,” said Check Point research.

Ransomware remains one of the most persistent and potentially cyber threats to organizations around the world. Despite being a known cybersecurity issue for at least a decade, attacks have become more disruptive, difficult to fix and financially costly.

Steps organizations can take to make the network robust against ransomware attacks include applying security patches and updates, enforcing multi-factor authentication on user accounts, and ensuring that the security team is well-resourced and has enough time to detect and examine potential red flags which might indicate attacks are in the network, prior to the ransomware being executed.