---
title: "Ransomware Report 2022: The Top 5 Ransomware and Malware Groups Making Strides this Year | DuoCircle"
description: "Ransomware and Malware attacks have been growing at an alarming rate, with more cybercriminal groups emerging and continually targeting industries worldwide."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/"
---

Quick Answer

Five ransomware and malware groups active in 2022, with predicted global ransomware costs hitting $265 billion by 2031 (up from $20 billion in 2021). LAPSUS$ (DEV-0537): exfiltrates by recruiting employees for admin access; in 2022 hit Impresa (January), NVIDIA (1TB stolen, February), and Microsoft and Okta (March). LockBit: RaaS specializing in double extortion using LockBit 2.0 auto-spreading tools; 2022 victims included Thales Group, the French Ministry of Justice, and Bridgestone Americas. BlackCat (ALPHV): emerged November 2021, code in Rust, targets system slowdowns to pressure ransom; 2022 hit Moncler ($3 million demand) and Oiltanking/Mabanaft (200+ German oil stations). Wizard Spider with Conti: faster custom AES with a public leak site; 2022 targets included Bay & Bay, Bank Indonesia, and Aluminerie Alouette; same group runs Ryuk. Vice Society: targets schools (Carthage R-9, Durham Johnston) and accounting firms (Optionis Group), encrypts data and leaks on dark web when ransom is refused.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Femail-security%2Fransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Ransomware%20Report%202022%3A%20The%20Top%205%20Ransomware%20and%20Malware%20Groups%20Making%20Strides%20this%20Year&url=undefined%2Fblog%2Femail-security%2Fransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Femail-security%2Fransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Femail-security%2Fransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year%2F&title=Ransomware%20Report%202022%3A%20The%20Top%205%20Ransomware%20and%20Malware%20Groups%20Making%20Strides%20this%20Year "Share on Reddit") [ ](mailto:?subject=Ransomware%20Report%202022%3A%20The%20Top%205%20Ransomware%20and%20Malware%20Groups%20Making%20Strides%20this%20Year&body=Check out this article: undefined%2Fblog%2Femail-security%2Fransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year%2F "Share via Email") 

![Ransomware and Malware Groups](https://media.mailhop.org/duocircle/images/2022/04/email-migration-service-6486.jpg) 

Ransomware and Malware attacks have been growing at an alarming rate, with more cybercriminal groups emerging and continually targeting industries worldwide. Ransomware is predicted to cost [$265 billion by 2031](https://cybersecurityventures.com/global-ransomware-damage-costs-predicted-to-reach-250-billion-usd-by-2031/), a significant increase from **$20 billion in 2021**, so it is advisable to privy yourself to the top ransomware and malware groups active in 2022, their key tactics, and prominent attacks to gain a vivid picture of the current ransomware scenario.

## 1\. LAPSUS$

DEV-0537, also known as the LAPSUS$ group, is an infamous cybercriminal gang that targets corporations for data exfiltration and extortion. The group has been around since 2021 and claimed responsibility for significant, **high-profile cyberattacks** demanding ransom.

**Key Tactic**: LAPSUS$ is known for its ransom demands where it exfiltrates an organization by enticing employees, gaining access to administrator accounts, and taking over the organization’s services.

_Prominent LAPSUS$ Attacks in 2022:_

- **Hijacking of Impresa**: The Portuguese media channel’s online [streaming services and websites](https://securityaffairs.co/wordpress/126236/cyber-crime/impresa-lapsus-ransomware.html) changed faces under the LAPSUS$ attack, demanding a ransom leveraging their control over the channel’s AWS in January 2022.
- **Exfiltration of NVIDIA**: [LAPSUS$ struck NVIDIA](https://analyticsindiamag.com/lapsus-hack-leaves-nvidia-in-a-tight-spot/) in February 2022, compromising the internal systems and stealing nearly 1TB of NVIDIA’s data with plans to leak the data in batches if NVIDIA failed to fulfil their ransomware demand.
- **Microsoft and Okta**: The [theft](/email-security/lapsus-breaches-microsoft-and-okta-the-event-the-impact-and-the-remedy/) of Microsoft’s source code and Bing, Maps, Cortana, and authentication service provider, Okta’s sensitive cloud service accounts in March 2022 is the most recent blow by LAPSUS$.

## 2\. LockBit

LockBit is another cybercrime syndicate that emerged in 2019 and has been posing a significant threat ever since. LockBit is widely known for its **RaaS** (Ransomware-as-a-Service) model and specializes in double extortion.

**Key Tactic**: LockBit follows the use of its automated data exfiltration tools, the latest one being LockBit 2.0, which spreads through the network automatically. LockBit follows a stealthy and silent approach and _ropes in organizations afterwards_ with their ransom demands.

[![ransomware attack](https://media.mailhop.org/duocircle/images/2022/04/office-365-to-office-365-migration-3586.jpg)](https://media.mailhop.org/duocircle/images/2022/04/office-365-to-office-365-migration-3586.jpg)

_Prominent LockBit Attacks in 2022:_

- **The Thales Ransom**: Lockbit [revealed](https://www.breakinglatest.news/health/cyber-%E2%80%8B%E2%80%8Battack-on-thales-group-lockbit-2-0-reported-stolen-data/) its exfiltration of the French electronics multinational, Thales Group, in January 2022 and threatened the release of sensitive data on the failure of their ransomware demand.
- **French Ministry of Justice**: LockBit also [demanded a ransom](https://www.politico.eu/article/infamous-ransomware-group-claims-it-hacked-frances-justice-ministry/#:~:text=An%20infamous%20cybercriminal%20group%20said,on%20a%20data%20leak%20site.) from the French Ministry of Justice in January 2022, after taking credit for encrypting Ministry files and threatening to release sensitive Ministry data on the dark web.
- **Exfiltration of Bridgestone Americas**: Tyre manufacturer Bridgestone also [suffered a ransomware attack](https://www.bleepingcomputer.com/news/security/bridgestone-americas-confirms-ransomware-attack-lockbit-leaks-data/) by LockBit in February 2022 when LockBit stole the manufacturer’s data and published a countdown meter with time remaining to publish stolen files if Bridgestone did not meet the demand.

## 3\. BlackCat

BlackCat is another cybercriminal group that provides RaaS and targets various organizations worldwide. The group is also called **ALPHV** and has been around since November 2021.

**Key Tactic**: BlackCat enjoys making its victims suffer by compromising the organization’s systems, exfiltrating the data, and attacking the primary system causing slowdowns, [denial of services](/email-security/impending-cybersecurity-threats-to-businesses-in-2022-and-beyond/), delayed operations, and more in a bid to demand ransom, using its ransomware strain coded in the Rust language.

_Prominent BlackCat / ALPHV Attacks in 2022:_

- **Moncler**: Moncler, the luxury fashion market leader from Italy, was [targeted by ALPHV](https://www.bleepingcomputer.com/news/security/fashion-giant-moncler-confirms-data-breach-after-ransomware-attack/) in January 2022, who stole Moncler’s data and leaked it on Tor. The attack began in December of last year, but the data was leaked this year as Moncler did not fulfill the $3 million ransom demand.
- **German Oil**: The German oil organizations Oiltanking and Mabanaft were huge targets of BlackCat’s [ransomware attack in February 2022](https://www.bloombergquint.com/business/-black-cat-ransomware-tied-to-attacks-on-germany-s-fuel-systems), which affected the services of over 200 oil stations in the country.

## 4\. Wizard Spider (Conti Ransomware Group)

Wizard Spider is another infamous ransomware group making headlines since 2020 with its ransomware, Conti. Conti is behind several high-profile ransomware attacks in the US and Europe and has been the talk of the town since its [warning to foes of Russia](https://www.reuters.com/technology/russia-based-ransomware-group-conti-issues-warning-kremlin-foes-2022-02-25/).

**Key Tactic**: Conti implements a special and faster ransomware software that uses its own AES encryption and operates a website where it **leaks sensitive documents**. Conti’s creator, Wizard Spider, is also behind the famous [Ryuk ransomware](/resources/ryuk-ransomware-attacks).

_Prominent Conti Attacks in 2022:_

- **Minnesota’s Bay & Bay**: Wizard Spider used Conti to target Bay & Bay trucking company in January 2022 by exploiting their Microsoft exchange server vulnerabilities. Bay & Bay [refused the ransomware demand](https://www.freightwaves.com/news/minnesota-trucking-company-hit-in-2nd-ransomware-attack) that led to the group’s leak of stolen Bay & Bay data on the dark web.
- **Indonesian Central Bank**: Bank Indonesia suffered a [ransomware](https://www.bleepingcomputer.com/news/security/indonesias-central-bank-confirms-ransomware-attack-conti-leaks-data/) attack in January 2022\. Wizard Spider stole employee data, took credit for the attack, and stated a theft of nearly 13.88 GB of data.
- **Canada’s Aluminerie Alouette**: Conti [targeted](https://www.theglobeandmail.com/business/article-ransomware-gang-conti-takes-credit-for-alouette-cyberattack/) Aluminerie Alouette, a leading metal producer, in March 2022\. The group published the details of the theft of Alouette’s data and credit for the attack on their website in a ransom demand.

[![cybercrime](https://media.mailhop.org/duocircle/images/2022/04/office-365-migration-service-7083.jpg)](https://media.mailhop.org/duocircle/images/2022/04/office-365-migration-service-7083.jpg)

## 5\. Vice Society

The Vice Society is another ransomware gang emerging as a rising force in [cybercrime](/content/email-security-services).

**Key Tactic**: The Vice Society has targeted many schools and is known for encrypting the data via malware, demanding ransoms in exchange for access and control.  
Prominent Vice Society Attacks in 2022:

**Missouri School**: Vice Society dumped information from Missouri’s Carthage R-9 district in January 2022 as the school did not offer a good ransom. The dump contained the information about human resources, files, and social security numbers of over 1000 workforce.  
**Durham Johnston**: UK’s Durham Johnston school was another school targeted by vice in January 2022\. They [leaked sensitive data](https://www.thenorthernecho.co.uk/news/19849617.ransomware-attack-durham-johnston-school/) of both students and staff on the failure of the ransom demand’s payment.  
**Optionis**: An accounting organization, Optionis Group, that oversees brands such as Parasol, Clearsky, etc., was [another victim](https://www.theregister.com/2022/02/08/optionis%5Fvice%5Fsociety/) of the Vice Society that leaked their data on the dark web in February 2022.

## Final Words

With the increasing availability of RaaS and cybercriminal groups recruiting for insider attacks, it is imperative to understand the ramifications of rising ransomware and malware attacks. As these threats are only bound to increase, you need to have adequate [anti-ransomware tools](/email/phishing-protection) and measures in place to _ensure your business does not suffer_, even in the worst-case scenario of being hit by a ransomware attack.

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  Email Security 8m  BIMI in 2026: What the Certificate Authority Does, and What Your DMARC Tool Does  May 5, 2026 ](/blog/bimi-2026-what-the-ca-does-what-your-dmarc-tool-does/)[  Email Security 8m  Designing A Custom Dkim Architecture For High-Volume Email Senders  Apr 28, 2026 ](/blog/designing-custom-dkim-architecture-for-high-volume-email-senders/)[  Email Security 12m  DMARC, SPF, and DKIM in 2026: Why Email Authentication Is Now a Regulatory Requirement, Not Just a Best Practice  Apr 29, 2026 ](/blog/dmarc-spf-dkim-2026-email-authentication-regulatory-requirement-best-practice/)[  Email Security 5m  Email Monitoring Tools: A Complete Guide to Protecting Your Email Ecosystem  May 7, 2026 ](/blog/email-monitoring-tools-guide-protecting-your-email-ecosystem-security/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Ransomware Report 2022: The Top 5 Ransomware and Malware Groups Making Strides this Year","description":"Ransomware and Malware attacks have been growing at an alarming rate, with more cybercriminal groups emerging and continually targeting industries worldwide.","url":"https://www.duocircle.com/blog/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/","datePublished":"2022-04-19T19:44:17.000Z","dateModified":"2025-05-29T13:18:31.000Z","dateCreated":"2022-04-19T19:44:17.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/"},"articleSection":"email-security","keywords":"","wordCount":1015,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/04/email-migration-service-6486.jpg","caption":"Ransomware and Malware Groups","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Email Security"},{"@type":"ListItem","position":3,"name":"Ransomware Report 2022: The Top 5 Ransomware and Malware Groups Making Strides this Year","item":"https://www.duocircle.com/blog/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Email Security","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Ransomware Report 2022: The Top 5 Ransomware and Malware Groups Making Strides this Year","item":"https://www.duocircle.com/blog/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Ransomware Report 2022: The Top 5 Ransomware and Malware Groups Making Strides this Year","description":"Ransomware and Malware attacks have been growing at an alarming rate, with more cybercriminal groups emerging and continually targeting industries worldwide.","url":"https://www.duocircle.com/blog/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/","datePublished":"2022-04-19T19:44:17.000Z","dateModified":"2025-05-29T13:18:31.000Z","dateCreated":"2022-04-19T19:44:17.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/email-security/ransomware-report-2022-the-top-5-ransomware-and-malware-groups-making-strides-this-year/"},"articleSection":"email-security","keywords":"","wordCount":1015,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/04/email-migration-service-6486.jpg","caption":"Ransomware and Malware Groups","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
