Ransomware operators are increasingly leveraging supply chain attacks and credential harvesting to expand their reach and maximize profits. Notable groups such as Qilin, Akira, Sinobi, INC Ransom, and Play have been identified as leading actors, with the Clop group repeatedly exploiting zero-day vulnerabilities in widely used software, including managed file transfer solutions and Oracle E-Business Suite, to compromise multiple organizations simultaneously. The volume of ransomware victims listed on data leak sites surged by one-third from September to October, according to Cyble, highlighting the persistent threat posed by these actors.
Despite a decrease in total ransom payments from $1.25 billion in 2023 to $814 million in 2024, ransomware groups are actively innovating to reverse this trend, including launching new affiliate programs and refining their attack techniques. However, some operations have suffered from sloppy coding, occasionally resulting in unrecoverable data. The continued evolution of ransomware tactics underscores the need for organizations to strengthen defenses against both direct and supply chain threats, as well as to monitor for credential harvesting activities that may precede future attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Analysis found that the Obscura ransomware strain was poorly coded, sometimes leaving victims unable to recover data even after paying a ransom.
Ransomware operators increasingly harvested credentials from edge devices, especially SonicWall SSL VPNs, to enable follow-on ransomware attacks against compromised organizations.
A newer ransomware actor, Scattered Lapsus$ Hunters, emerged with its own ransomware variant called ShinySp1d3r and an affiliate program, reflecting a move toward in-house tooling and profit retention.
The Clop ransomware group exploited zero-day vulnerabilities in Oracle E-Business Suite in a supply-chain-style campaign to steal data at scale from victim organizations.
Chainalysis tracked ransomware payments dropping from $1.25 billion in 2023 to $814 million in 2024, indicating reduced victim payments despite continued ransomware activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.