Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationcredential-access-methodcybercrime-service-ecosystemvendor-distribution-compromise

Ransomware Groups Innovate with Supply Chain Attacks and Credential Harvesting

Updated 3mo agoFirst seen Nov 28, 20252 sources

Ransomware operators are increasingly leveraging supply chain attacks and credential harvesting to expand their reach and maximize profits. Notable groups such as Qilin, Akira, Sinobi, INC Ransom, and Play have been identified as leading actors, with the Clop group repeatedly exploiting zero-day vulnerabilities in widely used software, including managed file transfer solutions and Oracle E-Business Suite, to compromise multiple organizations simultaneously. The volume of ransomware victims listed on data leak sites surged by one-third from September to October, according to Cyble, highlighting the persistent threat posed by these actors.

Despite a decrease in total ransom payments from $1.25 billion in 2023 to $814 million in 2024, ransomware groups are actively innovating to reverse this trend, including launching new affiliate programs and refining their attack techniques. However, some operations have suffered from sloppy coding, occasionally resulting in unrecoverable data. The continued evolution of ransomware tactics underscores the need for organizations to strengthen defenses against both direct and supply chain threats, as well as to monitor for credential harvesting activities that may precede future attacks.

Share:
Ransomware Groups Innovate with Supply Chain Attacks and Credential Harvesting
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Nov 28, 20257mo ago

Researchers note Obscura ransomware causes unrecoverable data loss

Analysis found that the Obscura ransomware strain was poorly coded, sometimes leaving victims unable to recover data even after paying a ransom.

Attackers use SonicWall SSL VPN credential harvesting for later intrusions

Ransomware operators increasingly harvested credentials from edge devices, especially SonicWall SSL VPNs, to enable follow-on ransomware attacks against compromised organizations.

Scattered Lapsus$ Hunters launches ShinySp1d3r and affiliate model

A newer ransomware actor, Scattered Lapsus$ Hunters, emerged with its own ransomware variant called ShinySp1d3r and an affiliate program, reflecting a move toward in-house tooling and profit retention.

Clop exploits Oracle E-Business Suite zero-days for data theft

The Clop ransomware group exploited zero-day vulnerabilities in Oracle E-Business Suite in a supply-chain-style campaign to steal data at scale from victim organizations.

Dec 31, 20241y ago

Chainalysis reports ransomware payments fell in 2024

Chainalysis tracked ransomware payments dropping from $1.25 billion in 2023 to $814 million in 2024, indicating reduced victim payments despite continued ransomware activity.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

41 LINKEDOpen in app
Organizations
29 linked
ChainalysisCybleCl0pMazda Motor CorporationZeroFoxCovewareKELAScattered Lapsus$ HuntersSOCRadarCanonAkiraMichelinBroadcomOracleSonicwallFogLapsus$ShinySp1d3rSinobiQilinHellcatRansomHubDragonForceINC RansomShinyHuntersPlayALPHV/BlackCatObscuraScattered Spider
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.