In a significant shift in the ransomware landscape, payments to attackers have decreased by approximately 35% year-over-year.
This decline is attributed to increased law enforcement actions, improved international collaboration, and a growing trend among victims to refuse ransom demands.
Here below we have mentioned all the key developments in 2024:-
Year | Total Payments
------|----------------
2023 | $1.25 billion
2024 | $813.55 million Ransomware Group | H1 2024 Payments | H2 2024 Payments
-----------------|------------------|------------------
LockBit | High | Decreased by 79% Negotiation Outcome
-------------------
Payments Made: ~30% As major groups face disruptions, new strains have emerged, often from rebranded or leaked code.
Chainalysis researchers noted that the ransomware operations have become faster, with negotiations starting within hours of data exfiltration.
The rise of lone actors and smaller groups focusing on smaller targets has become more prevalent.
Despite an increase in data leak site postings, which often serve as a proxy for ransomware events, actual payments have declined.
This inconsistency suggests that attackers may be overstating or fabricating victim claims to maintain relevance.
Ransom funds are primarily laundered through centralized exchanges (CEXs), personal wallets, and cross-chain bridges. There has been a notable decline in the use of mixers, likely due to sanctions and law enforcement actions.
The decrease in ransomware payments reflects a more resilient victim base and effective law enforcement strategies.
As the landscape continues to progress rapidly, so, understanding these trends is crucial for mitigating future threats.
Are you from SOC/DFIR Team? - Join 500,000+ Researchers to Analyze Cyber Threats with ANY.RUN Sandbox - Try for Free
A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…
Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…
SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…
OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…
The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions…
Salesforce has issued a critical security alert identifying "unusual activity" involving Gainsight-published applications connected to…