• Live Feeds
    • Press Releases
    • Insider Trading
    • FDA Approvals
    • Analyst Ratings
    • Insider Trading
    • SEC filings
    • Market insights
  • Analyst Ratings
  • Alerts
  • Subscriptions
  • AI Executive AssistantNEW
  • Settings
  • RSS Feeds
Quantisnow Logo
  • Live Feeds
    • Press Releases
    • Insider Trading
    • FDA Approvals
    • Analyst Ratings
    • Insider Trading
    • SEC filings
    • Market insights
  • Analyst Ratings
  • Alerts
  • Subscriptions
  • AI Executive AssistantNEW
  • Settings
  • RSS Feeds
PublishGo to AppAI Helper
    Quantisnow Logo

    © 2025 quantisnow.com
    Democratizing insights since 2022

    Services
    Live news feedsRSS FeedsAlertsPublish with Us
    Company
    AboutQuantisnow PlusContactJobsAI employees for your businessNEW
    Legal
    Terms of usePrivacy policyCookie policy

    Active Ransomware Threat Groups Up 30% in 2024

    10/8/24 6:00:00 AM ET
    $SCWX
    Computer Software: Prepackaged Software
    Technology
    Get the next $SCWX alert in real time by email

    Secureworks annual State of The Threat Report outlines cybercriminals response as law enforcement operations successfully cause widespread disruption to ransomware operations

    ATLANTA, Oct. 8, 2024 /PRNewswire/ -- Secureworks® (NASDAQ:SCWX) 2024 State of the Threat Report has revealed a 30% year-over-year rise in active ransomware groups, which demonstrates fragmentation of an established criminal ecosystem. 31 new groups entered the ransomware ecosystem during the last 12 months, and based on numbers of victims listed the three most active groups are:

    www.secureworks.com (PRNewsfoto/SecureWorks, Inc.)

    1. LockBit:The long established 'top dog' of ransomware groups accounted for 17% of listings, down 8% from last year, proving even further how the takedown has impacted their operations.
    2. PLAY: The second most active group, PLAY doubled its victim count year-over-year.
    3. RansomHub: A new group, emerging only a week after the LockBit takedown, is already the third most active group with 7% of the share of victims listed.

    A landscape previously dominated by a few, is now home to a broader set of emerging ransomware players. As smaller groups look to become established, it means there is less repeatability and structure in how they operate and organizations need to continue to remain alert for a wider variety of tactics. This year's median dwell time of 28 hours reflects the newness of these partnerships. While some clusters of groups are executing fast 'smash-and-grab' attacks within hours, others spend hundreds of days in networks in the most extreme cases. As the new ecosystem continues to take shape, we can expect to see further variation and shifts in dwell times and methodology.

    The annual State of the Threat Report examines the cybersecurity landscape from June 2023 to July 2024. Additional key findings include:

    • Law enforcement activity targeting GOLD MYSTIC (LockBit) and GOLD BLAZER (BlackCat/ALPV) caused significant disruption to the status quo of the ransomware operating landscape.
    • The number of active ransomware groups using "name and shame" leak sites grew 30% year-over-year.
    • Despite this growth in ransomware groups, victim numbers did not rise at the same pace, showing a significantly more fragmented landscape posing the question of how successful these new groups might be.
    • Scan-and-exploit and stolen credentials remain the two largest initial access vectors (IAV) observed in ransomware engagements based on our observations.
    • Observed increase in adversary-in-the-middle (AiTM) attacks – a notable and concerning trend for cyber defenders.
    • AI is growing in use and in variation for cybercriminals – expanding the scale and credibility of existing scams like CEO fraud or "obituary pirates."

    Shifting Sands of Ransomware

    "Ransomware is a business that is nothing without its affiliate model. In the last year, law enforcement activity has shattered old allegiances, reshaping the business of cybercrime. Originally chaotic in their response, threat actors have refined their business operations and how they work. The result is a larger number of groups, underpinned by substantial affiliate migration," said Don Smith, VP Threat Intelligence, Secureworks Counter Threat Unit™ (CTU™). "As the ecosystem evolves, we have entropy in threat groups, but also unpredictability in playbooks, adding significant complexity for network defenders."

    AiTM and AI as Growing Threats

    In the past year, threat actors are increasingly stealing credentials and session cookies to gain access by using AiTM attacks. This potentially reduces the effectiveness of some types of MFA, a worrying trend for network defenders. These attacks are facilitated and automated by phishing kits that are available for hire on underground marketplaces and Telegram. Popular kits include Evilginx2, EvilProxy and Tycoon2FA.

    As AI tools have become widespread and readily available, it was inevitable that cybercriminals would take note as they look to scale. Since mid-February 2023, Secureworks CTU researchers have observed an increase in posts on underground forums about OpenAI ChatGPT and how it can be employed for nefarious purposes. Much of the discussion relates to relatively low-level activity including phishing attacks and basic script creation.

    "The cybercrime landscape continues to evolve, sometimes minor, occasionally more significant. The growing use of AI lends scale to threat actors, however the increase of AiTM attacks presents a more immediate problem for enterprises, reinforcing that identity is the perimeter and should cause enterprises to take stock and reflect on their defensive posture," continued Smith.  

    One novel example of AI being used by threat actors, as observed by Secureworks researchers, was the role it played in a fraud perpetrated by so-called obituary pirates. Threat actors monitored Google trends following a death to identify interest in obituaries and then used generative AI to create lengthy tributes on sites that were manipulated to the top of Google search results by SEO poisoning. They then directed users to other sites pushing adware or potentially unwanted programs.

    State-Sponsored Threat Activity – A Summary

    The report also examines the significant activities and trends in the behavior of state-sponsored threat groups belonging to China, Russia, Iran, and North Korea. This year, we are also including threat group activity from Hamas, which has seen a notable increase since the outbreak of the Israel-Hamas war, now spilling over into the public domain and our aperture. The primary drivers for these countries are geopolitical.

    China:

    Chinese cyber activity has continued to track with previous Secureworks observations. Their aims are broadly focused on information theft for political, economic, and military gain. Much of this activity targeted at industrial sectors that align with the high-level objectives of the Chinese Communist Party's (CCP) Five Year Plan. In October 2023, the heads of the US, UK, Australian, Canadian, and New Zealand security agencies warned of the "epic scale" of Chinese espionage. State-sponsored threat actors were not immune to the law enforcement activity. In March 2024, the US State Department unsealed indictments against seven named individuals all part of the BRONZE VINEWOOD threat group. The indictments contain details of an extensive campaign of intrusions committed by the group over more than a decade of malicious activity. In the same month, the UK government stated that China was responsible for two malicious campaigns against the UK Electoral Commission between 2021 and 2022. However, no information was released about the group responsible.

    Iran:

    Iranian internal and external cyber activity remained driven by its political imperatives. Internationally, Iran primarily focuses on Israel, regional adversaries including Saudi Arabia, United Arab Emirates and Kuwait, and the US. Iran makes regular use of fake hacktivist personas to target enemies, allowing itself plausible deniability. There are two primary Iranian sponsors of cyber activity: the Islamic Revolutionary Guard Corp (IRGC) and the Ministry of Intelligence and Security (MOIS).

    North Korea:

    North Korean threat actors continued their pursuit of revenue generation via cryptocurrency theft and sophisticated fraudulent employment schemes to gain access to Western jobs. They were persistent in targeting the IT sector and weaknesses in the supply chain. There was a major focus on entities in the US, South Korea, and Japan. These activities were set within the geopolitical context of an increased willingness on the part of North Korea to work with Russia and Iran, with the intent to foster relations with countries that are prepared to confront related, perceived enemies despite international sanctions.

    Hamas:

    Secureworks tracks three threat groups: ALUMINUM SHADYSIDE, ALUMINUM SARATOGA and ALUMINUM THORN considered to be aligned with Hamas, the militant group that governs the Gaza Strip. The outbreak of the Israel-Hamas war in October 2023 led to an uptick of cyber activity targeted at Israel and countries perceived to be aligned with them. However, much of that activity is thought to have been the work of hacktivist groups and personas masquerading as Palestinian but more likely linked to Iran or Russia.

    Russia:

    The war in Ukraine continues to drive Russian state-sponsored cyber activity, both in Ukraine and abroad. Groups associated with all three of Russia's intelligence agencies were active throughout the past year. CTU researchers assess that Russia's most aggressive use of cyber capabilities in sabotage operations will remain focused on critical infrastructure targets within Ukraine. One notable example of this kind of activity this year was IRON VIKING's cyber espionage attacks against battlefield control systems used by Ukrainian defense forces.

    State of the Threat Report 2024

    This 8th edition of Secureworks State of the Threat Report provides a concise analysis of how the global cybersecurity threat landscape has evolved over the last 12 months. The information within the report is drawn from the Secureworks CTU firsthand observations of threat actor tooling and behaviors and includes actual incidents. Our annual threat analysis provides a deep dive insight into the threats our team has observed on the front line of cybersecurity.

    The Secureworks State of the Threat Report can be read in full here: https://www.secureworks.com/resources/rp-state-of-the-threat-2024 

    About Secureworks

    Secureworks (NASDAQ:SCWX) is a global cybersecurity leader that secures human progress with Secureworks® Taegis™, a SaaS-based, open XDR platform built on 20+ years of real-world detection data, security operations expertise, and threat intelligence and research. Taegis is embedded in the security operations of thousands of organizations around the world who use its advanced, AI-driven capabilities to detect advanced threats, streamline and collaborate on investigations, and automate the right actions.

    Connect with Secureworks via LinkedIn and Facebook or Read the Secureworks Blog

    Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/active-ransomware-threat-groups-up-30-in-2024-302267728.html

    SOURCE Secureworks, Inc.

    Get the next $SCWX alert in real time by email

    Crush Q3 2025 with the Best AI Executive Assistant

    Stay ahead of the competition with Tailforce.ai - your AI-powered business intelligence partner.

    AI-Powered Inbox
    Context-aware email replies
    Strategic Decision Support
    Get Started with Tailforce.ai

    Recent Analyst Ratings for
    $SCWX

    DatePrice TargetRatingAnalyst
    12/6/2021$15.00 → $16.00Equal-Weight
    Morgan Stanley
    12/3/2021$20.00 → $19.00Sector Perform
    RBC Capital
    More analyst ratings

    $SCWX
    Press Releases

    Fastest customizable press release news feed in the world

    See more
    • Sophos Completes Secureworks Acquisition

      OXFORD, United Kingdom and ATLANTA, Feb. 03, 2025 (GLOBE NEWSWIRE) -- Sophos and Secureworks® (NASDAQ:SCWX), two global cybersecurity pioneers that have innovated and redefined services and technology solutions for defeating cyberattacks, today announced the completion of Sophos' acquisition of Secureworks. The all-cash transaction values Secureworks at approximately $859 million. With the completion of the acquisition, Secureworks' common stock has ceased trading on Nasdaq. Sophos is backed by Thoma Bravo, a leading software investment firm. With this acquisition, Sophos is now the leading pure-play cybersecurity provider of Managed Detection and Response (MDR) services, supporting more

      2/3/25 9:17:06 AM ET
      $DELL
      $SCWX
      Computer Manufacturing
      Technology
      Computer Software: Prepackaged Software
    • Secureworks Announces Third Quarter Fiscal 2025 Results

      ATLANTA, Dec. 4, 2024 /PRNewswire/ -- Secureworks® (NASDAQ:SCWX), a global leader in cybersecurity, today announced financial results for its third quarter fiscal 2025, which ended on November 1, 2024. Key Highlights Taegis™ third quarter revenue grew 6% year-over-year to $71.4 million.Total annual recurring revenue (ARR) grew to $288.8 million, an increase of 4% on a year-over-year basis.Taegis GAAP gross margin and non-GAAP gross margin continued to expand year-over-year in the third quarter, reaching 72% and 75%, respectively."With a 30% rise in active ransomware groups yea

      12/4/24 7:00:00 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Secureworks to Report Third Quarter Fiscal 2025 Financial Results on December 4, 2024

      ATLANTA, Nov. 20, 2024 /PRNewswire/ -- Secureworks® (NASDAQ:SCWX) today announced that it plans to release its third quarter fiscal 2025 financial results on Wednesday, December 4, 2024, before the open of regular U.S. stock market trading hours.  Secureworks will not be hosting a quarterly earnings conference call in light of the pending transaction with Sophos. About SecureworksSecureworks (NASDAQ:SCWX) is a global cybersecurity leader that secures human progress with Secureworks Taegis™, a SaaS-based, open XDR platform built on 20+ years of real-world detection data, securi

      11/20/24 4:05:00 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology

    $SCWX
    Insider Trading

    Insider transactions reveal critical sentiment about the company from key stakeholders. See them live in this feed.

    See more
    • SEC Form 4 filed by Director Dell Michael S

      4 - SecureWorks Corp (0001468666) (Issuer)

      2/5/25 4:26:46 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Director Daley Pamela returned 248,783 shares to the company, closing all direct ownership in the company (SEC Form 4)

      4 - SecureWorks Corp (0001468666) (Issuer)

      2/4/25 6:44:43 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Director Hawkins Mark J returned 204,140 shares to the company, closing all direct ownership in the company (SEC Form 4)

      4 - SecureWorks Corp (0001468666) (Issuer)

      2/4/25 6:43:30 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology

    $SCWX
    Insider Purchases

    Insider purchases reveal critical bullish sentiment about the company from key stakeholders. See them live in this feed.

    See more
    • Gagnon Neil bought $55,768 worth of shares (9,531 units at $5.85), increasing direct ownership by 1% to 628,058 units (SEC Form 4)

      4 - SecureWorks Corp (0001468666) (Issuer)

      6/5/24 4:13:40 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Gagnon Neil bought $106,676 worth of shares (17,823 units at $5.99), increasing direct ownership by 2% to 610,947 units (SEC Form 4)

      4 - SecureWorks Corp (0001468666) (Issuer)

      4/25/24 5:15:05 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Gagnon Neil bought $38,511 worth of shares (5,731 units at $6.72), increasing direct ownership by 0.97% to 597,149 units (SEC Form 4)

      4 - SecureWorks Corp (0001468666) (Issuer)

      2/14/24 5:12:47 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology

    $SCWX
    SEC Filings

    See more
    • SEC Form SCHEDULE 13G filed by SecureWorks Corp.

      SCHEDULE 13G - SecureWorks Corp (0001468666) (Subject)

      2/13/25 12:44:53 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • SEC Form 15-12G filed by SecureWorks Corp.

      15-12G - SecureWorks Corp (0001468666) (Filer)

      2/13/25 7:00:25 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • SEC Form S-8 POS filed by SecureWorks Corp.

      S-8 POS - SecureWorks Corp (0001468666) (Filer)

      2/3/25 4:37:45 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology

    $SCWX
    Analyst Ratings

    Analyst ratings in real time. Analyst ratings have a very high impact on the underlying stock. See them live in this feed.

    See more
    • Morgan Stanley reiterated coverage on SecureWorks with a new price target

      Morgan Stanley reiterated coverage of SecureWorks with a rating of Equal-Weight and set a new price target of $16.00 from $15.00 previously

      12/6/21 10:34:33 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • RBC Capital reiterated coverage on SecureWorks with a new price target

      RBC Capital reiterated coverage of SecureWorks with a rating of Sector Perform and set a new price target of $19.00 from $20.00 previously

      12/3/21 7:48:54 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • RBC Capital reiterated coverage on SecureWorks with a new price target

      RBC Capital reiterated coverage of SecureWorks with a rating of Sector Perform and set a new price target of $15.00 from $14.00 previously

      6/4/21 7:33:22 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology

    $SCWX
    Financials

    Live finance-specific insights

    See more
    • Secureworks Announces Third Quarter Fiscal 2025 Results

      ATLANTA, Dec. 4, 2024 /PRNewswire/ -- Secureworks® (NASDAQ:SCWX), a global leader in cybersecurity, today announced financial results for its third quarter fiscal 2025, which ended on November 1, 2024. Key Highlights Taegis™ third quarter revenue grew 6% year-over-year to $71.4 million.Total annual recurring revenue (ARR) grew to $288.8 million, an increase of 4% on a year-over-year basis.Taegis GAAP gross margin and non-GAAP gross margin continued to expand year-over-year in the third quarter, reaching 72% and 75%, respectively."With a 30% rise in active ransomware groups yea

      12/4/24 7:00:00 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Secureworks to Report Third Quarter Fiscal 2025 Financial Results on December 4, 2024

      ATLANTA, Nov. 20, 2024 /PRNewswire/ -- Secureworks® (NASDAQ:SCWX) today announced that it plans to release its third quarter fiscal 2025 financial results on Wednesday, December 4, 2024, before the open of regular U.S. stock market trading hours.  Secureworks will not be hosting a quarterly earnings conference call in light of the pending transaction with Sophos. About SecureworksSecureworks (NASDAQ:SCWX) is a global cybersecurity leader that secures human progress with Secureworks Taegis™, a SaaS-based, open XDR platform built on 20+ years of real-world detection data, securi

      11/20/24 4:05:00 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Secureworks Announces Second Quarter Fiscal 2025 Results

      ATLANTA, Sept. 5, 2024 /PRNewswire/ -- Secureworks (NASDAQ:SCWX), a global leader in cybersecurity, today announced financial results for its second quarter fiscal 2025, which ended on August 2, 2024. Key Highlights Taegis™ second quarter revenue grew 7% year-over-year to $71.2 million.Total annual recurring revenue (ARR) grew to $290 million, an increase of 5% on a year-over-year basis.Taegis GAAP gross margin and non-GAAP gross margin continued to expand year-over-year in the second quarter, reaching 71.8% and 74.3%, respectively."In a world where we rely on technology, comp

      9/5/24 7:00:00 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology

    $SCWX
    Large Ownership Changes

    This live feed shows all institutional transactions in real time.

    See more
    • Amendment: SEC Form SC 13G/A filed by SecureWorks Corp.

      SC 13G/A - SecureWorks Corp (0001468666) (Subject)

      12/6/24 3:33:53 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Amendment: SEC Form SC 13G/A filed by SecureWorks Corp.

      SC 13G/A - SecureWorks Corp (0001468666) (Subject)

      11/20/24 6:22:48 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Amendment: SEC Form SC 13G/A filed by SecureWorks Corp.

      SC 13G/A - SecureWorks Corp (0001468666) (Subject)

      11/14/24 4:28:33 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology

    $SCWX
    Leadership Updates

    Live Leadership Updates

    See more
    • Secureworks Appoints William Cary to its Board of Directors

      ATLANTA, March 21, 2024 /PRNewswire/ -- Secureworks (NASDAQ:SCWX), a global leader in cybersecurity, today announced that it has appointed William (Bill) H. Cary to its Board of Directors and to serve as Chair of the Audit Committee. "Bill's breadth and depth of financial and operational expertise adds to the existing strength of our Board. As we continue to focus on our growth strategy and delivering shareholder value with our leading, open cybersecurity platform, we will greatly benefit from Bill's insights and experience driving success in fast-paced markets. We are fortuna

      3/21/24 4:25:00 PM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Secureworks Appoints Michael Aiello As Chief Technology Officer

      Former Product Lead for Google Cloud Security Will Accelerate Growth as Business Transformation Continues ATLANTA, July 12, 2022 /PRNewswire/ -- Secureworks® (NASDAQ:SCWX), a global leader in cybersecurity, today announced that it has appointed Michael Aiello as its new Chief Technology Officer (CTO). Aiello will play a pivotal role in setting the company's long-term strategic vision to define the next horizon of cybersecurity, accelerating its business transformation and championing customers to deliver enhanced security outcomes. Aiello will report directly into President and CEO, Wendy Thomas.

      7/12/22 8:03:00 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology
    • Secureworks Welcomes Tracey Mustacchio as Chief Marketing Officer

      ATLANTA, June 28, 2021 (GLOBE NEWSWIRE) -- Secureworks® (NASDAQ:SCWX), a global leader in cybersecurity, today announced the appointment of Tracey Mustacchio as its new Chief Marketing Officer. As CMO, Ms. Mustacchio is leading Secureworks' global growth and marketing strategies at a pivotal time for the Company, as it combines its years of security expertise with a new security analytics and operations platform to help organizations detect, investigate, and respond to advanced threats more quickly and effectively. Ms. Mustacchio reports to incoming Secureworks CEO Wendy K. Thomas. New leadership appointments are bold steps in Secureworks' drive to offer increasingly innovative technolo

      6/28/21 9:00:00 AM ET
      $SCWX
      Computer Software: Prepackaged Software
      Technology