Ransomware is no longer the work of lone hackers. Today’s most damaging attacks are carried out by organized criminal enterprises with dedicated developers, negotiators, and affiliates, operating ransomware-as-a-service (RaaS) platforms that have extorted billions from businesses across every industry. If your organization has not assessed its exposure to these groups, the threat is real. DCG’s incident response services respond to active attacks from every major ransomware operator, this guide explains who they are and how they work.
According to Chainalysis, ransomware payments surpassed $1 billion in 2023 – the highest level ever recorded. At the same time, Verizon reports ransomware is involved in nearly a quarter of all breaches, while IBM Security found it takes an average of 277 days to identify and contain an attack. With recovery costs exceeding $1.8 million according to Sophos, the need for rapid incident response has never been more critical.Â
The majority of that revenue flowed to fewer than a dozen dominant groups. Understanding their methods is the first step toward building defenses that can stop them.

The RaaS Business Model Changed Everything and Made Ransomware Harder to Stop
Affiliate Networks
Most major ransomware groups no longer operate like traditional malware authors who write code and deploy it themselves. They run affiliate programs, recruiting experienced threat actors who deploy their ransomware in exchange for a percentage of ransom proceeds. This model means that a single ransomware brand can generate dozens of simultaneous attacks across unrelated industries.
Double Extortion
Nearly every major ransomware group now uses double extortion: encrypting files and threatening to publish stolen data on public leak sites if the ransom is not paid. This creates pressure even for organizations with functioning backups. If sensitive customer data was stolen before encryption, a working restore does not resolve the threat.
Is paying the ransom the only option when attackers threaten to publish stolen data?
The 15 Most Dangerous Ransomware Groups Active Against U.S. Businesses
LockBit
LockBit has operated the most prolific ransomware-as-a-service platform of the past three years, accounting for more attributed attacks than any other group. Their affiliate program is technically sophisticated, offering speed-optimized encryption and a self-service negotiation portal. Despite law enforcement disruption in 2024, LockBit has demonstrated repeated capacity to rebuild and continue operations.
Black Basta
Black Basta emerged in 2022 and quickly established itself as one of the most aggressive double-extortion operators. The group is believed to include former members of the Conti organization and has targeted critical infrastructure, healthcare, and professional services firms. Their initial access typically involves phishing and exploitation of known vulnerabilities in internet-facing services.
Clop
Clop is responsible for some of the largest mass-exploitation ransomware campaigns on record, most notably attacks on the MOVEit file transfer platform that compromised hundreds of organizations simultaneously. Rather than encrypting files and demanding ransom from each victim individually, Clop often focuses on data theft and threatens publication. Their campaigns are characterized by speed and scale.
BlackCat / ALPHV
BlackCat (also known as ALPHV) was technically advanced and uniquely operated in multiple operating system environments including Windows, Linux, and VMware ESXi, meaning they could encrypt both workstations and virtual infrastructure in a single attack. Despite a law enforcement takedown in late 2023, the group’s affiliate infrastructure remained active.
Hive
The FBI infiltrated Hive’s infrastructure in 2022 and 2023, recovering decryption keys for over 300 victims and preventing an estimated $130 million in ransom payments before dismantling the operation. Hive had targeted over 1,500 organizations in 80 countries, with a particular focus on healthcare.
Ryuk
Ryuk is one of the earliest enterprise-focused ransomware operators and pioneered the model of targeting large organizations rather than individuals. Ryuk attacks typically followed weeks of network access using TrickBot or BazarLoader malware, meaning by the time the ransomware deployed, attackers had already mapped the environment and exfiltrated data. The group is believed to have collected over $150 million in ransoms.
Conti
Conti was among the most professionally organized ransomware operations in history before internal data leaks and law enforcement pressure disrupted it in 2022. The leaks revealed a corporate-style operation with HR, IT support, and specialized attack teams. Former Conti members are believed to have seeded several successor groups including Black Basta.
REvil / Sodinokibi
REvil was responsible for the Kaseya VSA attack that simultaneously compromised hundreds of managed service providers and their clients in 2021. At their peak, REvil earned an estimated $200 million in a single year. Law enforcement operations disrupted the group in late 2021, though former members reappeared in subsequent operations.
AvosLocker
AvosLocker targeted critical infrastructure sectors including healthcare, financial services, and government. The group was notable for using legitimate remote administration tools, specifically AnyDesk, for persistence, making detection harder. CISA issued a specific advisory on AvosLocker TTPs in 2023.
Vice Society
Vice Society disproportionately targeted educational institutions and healthcare organizations in the U.S. and UK. Their attacks on school districts caused significant disruption and data exposure. Unlike some groups, Vice Society sometimes skipped encryption entirely and relied solely on data theft and extortion, a trend that other groups have since adopted.
Medusa
Medusa emerged as a significant threat in 2023, operating a public leak site and running a RaaS model that attracted experienced affiliates. The group has targeted manufacturing, education, and government sectors. Their aggressive negotiation tactics and willingness to publish data quickly after deadlines have made them particularly damaging.
Play
Play ransomware gained attention for targeting municipalities and critical infrastructure, with attacks on systems in California and across the U.S. The group exploits vulnerabilities in internet-facing systems and uses custom tools that complicate detection. Their attacks on public sector organizations have drawn significant law enforcement attention.
Scattered Spider
Scattered Spider is notable for using social engineering rather than purely technical exploits to gain initial access. The group has used SIM swapping, phishing, and help desk impersonation to compromise large enterprise environments. Their targeting of MGM Resorts and Caesars Entertainment in 2023 demonstrated their capability against major organizations with mature security programs.
Akira
The FBI calls Akira a ‘top five’ ransomware variant. Akira emerged in 2023 and quickly built a significant victim count across manufacturing, education, and healthcare. The group uses double extortion and operates a leak site. Security researchers have noted their encryption implementation has occasionally contained flaws, though organizations should not rely on this.
8Base
8Base operates primarily as a data theft and extortion group but also deploys ransomware when advantageous. Their targets have spanned professional services, construction, and healthcare. The group claims to represent ‘honest pen testers’ in communications, though their actual TTPs indicate sophisticated criminal operations.
The pattern across these groups is consistent: prolonged network access before encryption, credential theft, data exfiltration, and targeted attacks against backup infrastructure. Defending against them requires the same depth of approach.
If an attack is already underway, does knowing the threat actor group actually change the response?
| Group | Model | Primary Targets |
| LockBit | RaaS / Mass affiliate | All sectors |
| Black Basta | Targeted / Double extortion | Healthcare, professional services |
| Clop | Mass exploitation | Finance, legal, government |
| BlackCat / ALPHV | Cross-platform / RaaS | Healthcare, infrastructure |
| Ryuk | Enterprise targeted | Healthcare, finance, public sector |
| Conti | Corporate RaaS (disrupted) | All enterprise sectors |
| REvil | RaaS (disrupted) | MSPs, manufacturing, legal |
| AvosLocker | RaaS / RAT-enabled | Healthcare, finance, government |
| Vice Society | Data theft focus | Education, healthcare |
| Hive | RaaS (dismantled) | Healthcare, critical infrastructure |
FAQs: Ransomware Threat Groups
1. Which ransomware group is most active in 2024?
LockBit maintained the highest attack volume through early 2024, though law enforcement disruption reduced their capacity. Black Basta and Akira have increased activity in the vacuum.
2. Do ransomware groups actually delete stolen data after payment?
There is no guarantee, and no way to verify it. Law enforcement and security researchers have documented cases where groups continued threatening victims or sold data even after receiving payment.
3. Can ransomware groups be negotiated with?
Yes, most groups operate negotiation portals, but engaging without legal counsel and cyber insurance coordination is risky. Organizations should never negotiate without professional guidance.
4. Are smaller businesses targeted by these groups?
Yes. RaaS affiliates often prefer smaller organizations with weaker defenses. Mid-market and SMB companies represent a significant share of ransomware victims.
5. What should we do if we recognize the ransomware group from the ransom note?
Note the group name and contact your incident response provider immediately, identification helps inform negotiation strategy, data exfiltration risk, and recovery approach.
If your network has already been accessed, identifying the attackers is step one, but step two is knowing what to do next. Our ransomware attack response guide covers the first 24 hours in detail.
Stay Ahead of the Threat
Understanding the aftermath of an attack is only half the battle. To see how professionals piece together the puzzle after an incident, check out our complete digital forensics investigation process explained.
Next up: Before ransomware deploys, attackers leave traces. Learn to read them in our guide on network breach warning signs, the indicators most teams miss until it is too late.







































