Despite the U.S. Department of Justice's disruption of LockBit's operations on February 20, 2024, the group's acts of extortion experienced only a temporary decline before rapidly recovering. The result was a 1.74% increase in LockBit's acts of extortion by the end of Q1 2024 compared to Q4 2023.This news comes via the Q1 2024 Cyber Threat Report from Nuspire, an MSSP specializing in managed detection and response (MDR) and managed endpoint detection and response (EDR) solutions.The report spotlights a 3.69% rise in ransomware activities from Q4 2023, punctuating the persistent threat ransomware groups pose.Additionally, Nuspire reports that dark web market activity saw a “staggering” 58.16% increase in listings, indicating significant growth in the trade of stolen data and illicit goods.Here are other key findings from Nuspire’s report:
- The manufacturing sector, crucial to supply chains and rich in intellectual property, faced a jump in ransomware attacks from LockBit and CL0P. The growth in attacks highlights the vulnerabilities this industry often faces resulting from complex IT/OT systems, underinvestment in cybersecurity and the sector's historical prioritization of operational continuity over security measures.
- Listings on dark web marketplaces featuring Lumma Stealer saw a significant increase, more than doubling from Q4 2023. Lumma Stealer emerged in 2023 and quickly became a leader in infostealing malware.




