Home > Cyber News > The Most Prevalent Ransomware Variants in Q4 of 2021

The Most Prevalent Ransomware Variants in Q4 of 2021

The Most Prevalent Ransomware Variants in Q4 of 2021
A new Intel 471 whitepaper throws light on the ransomware variants detected in the fourth quarter of 2021. 722 ransomware attacks were detected during the fourth quarter of last year, which is an increase of 110 attacks recorded from the third quarter.

The most prevalent ransomware variants for the said period include LockBit 2.0, Conti, Pysa and Hive. The most affected sectors were consumer and industrial products, professional services and consulting, real estate, healthcare and life sciences, technology, media and telecommunications, among others. As for regions, most attacks took place in North America, Europe, Asia, South America, Oceania, Middle East, Central America and Africa, the report said.

LockBit 2.0

“Despite its relatively short period of operation, the LockBit 2.0 ransomware continued to be the most prominent variant in the fourth quarter of 2021,” the researchers pointed out.

Countries with the highest number of LockBit 2.0 attacks include the U.S., Italy, Germany, France, and Canada. “LockBit 2.0 allegedly targeted another 39 countries, however, they amounted to less than 2.7% of the total number of ransomware events associated with this variant,” Intel 471 added.

Conti Ransomware

Conti ransomware is the only family that was reported in all quarterly reports the company released in 2021. It was the most deployed variant in the second quarter of 2021. Countries with highest impact by Conti from October 2021 to December 2021 included the U.S., Germany, Italy, Canada, and Australia.

Last year, Conti was equipped with the capability to destroy victims’ backups.

PYSA Ransomware

PYSA ransomware was first observed in December 2019 and it is most likely a version of the Mespinoza ransomware. The sector with highest impact by PYSA was the public sector, with attacks against organizations such as South Africa’s Department of Justice and Constitutional Development, the U.S. city Bridgeport, Connecticut, and the U.K.-based Kent County Council.

Hive Ransomware

Hive attacks mostly affected life science and healthcare organizations, with the U.S. being the most attacked country by this ransomware.

On a different note, a group of academics from South Korea’s Kookmin University recently discovered a way to decipher Hive. Apparently, the researchers were able to “recover the master key for generating the file encryption key without the attacker’s private key, by using a cryptographic vulnerability identified through analysis.”

Milena Dimitrova

An inspired writer and content manager who has been with SensorsTechForum since the project started. A professional with 10+ years of experience in creating engaging content. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

More Posts

Follow Me:

Leave a Comment

Your email address will not be published. Required fields are marked *

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree