The report highlights how most IT and security teams lack comprehensive information on all existing vulnerabilities, with large gaps on even the most damaging threats
Ivanti Inc., provider of the Neurons automation platform that discovers, manages, protects and supports IT assets from the cloud to the edge, presents the results of the second and third quarter 2022 Ransomware Index Report created in collaboration with Cyber Security Works, Certifying Numbering Authority (CNA) and with Cyware, leading provider of the technology platform for the design of Cyber Fusion Centers. The report recorded a 466% increase in ransomware attacks from 2019 to today and how this typology is increasingly used to anticipate international conflicts, as in the case of the Russian-Ukrainian one and in cyberwar between Iran and Albania.
Ransomware clusters are growing in volume and sophistication, with 35 ransomware-associated vulnerabilities in the first three quarters of 2022 and 159 active exploits. Additionally, a lack of sufficient data and clear threat context hinders organizations from applying effective patches, exposing them to vulnerabilities.
The report identified 10 new ransomware families (Black Basta, Hive, BianLian, BlueSky, Play, Deadbolt, H0lyGh0st, Lorenz, Maui and NamPoHyu), which help bring their overall number to 170. With 101 CVEs assigned to phishing attacks, it is clear that ransomware groups are increasingly using these techniques to lure unwitting victims with the aim of delivering a malicious playload to them. Pegasus is an example of this: through a simple phishing message, hackers created access to the backdoor which, by exploiting the iPhone's vulnerabilities, led to the violation of information and the compromise of internationally important victims.
Ransomware then needs human interaction and the phenomenon of phishing as the only attack vector. In the investigation following the MITER ATT&CK framework to identify tactics, techniques and procedures used to compromise an organization, 323 new vulnerabilities associated with ransomware were analyzed and identified. Among these, 57 lead to obtaining complete control of the system, from initial access to data exfiltration, while two new vulnerabilities (CVE-2021-40539 and CVE-2022-26134) were exploited by groups such as AvosLocker and Cerber, anticipating their inclusion in the National Vulnerability Database (NVD) by a few days. These incidents indicate that organizations that rely solely on NVD to apply patches are at risk of cyberattacks.
The report also found that CISA's Known Exploited Vulnerabilities (KEV) database that provides U.S. public sector entities and government agencies with a list of vulnerabilities to be applied by a deadline was missing 124 vulnerabilities associated with ransomware.
Srinivas Mukkamala, Chief Product Officer at Ivanti, states, "IT and security teams urgently need to adopt a risk-based approach to vulnerability management to defend against ransomware attacks and other threats. This is achieved by implementing automated technology that can correlate data from disparate sources (network scanners, internal and external vulnerability databases, and penetration tests), quantify risk, provide early warnings, predict attacks, and prioritize remediation efforts. Organizations that continue to rely on traditional vulnerability management practices, such as using the NVD and other public databases to prioritize and apply patches to vulnerabilities risks being subjected to several cyberattacks.”
Further highlighting the need to replace traditional threat protection processes is the fact that many of today's antivirus solutions fail to detect many vulnerabilities, and the same research highlighted that as many as 18 ransomware-related vulnerabilities are not detected by the most popular antiviruses.
Aaron Sandeen, CEO of Cyber Security Works said: "The inability of antivirus solutions to detect exposed vulnerabilities is a serious problem. Organizations must adopt an attack surface management solution capable of detecting vulnerabilities in all assets in the company."
The research also shows the impact of ransomware on critical infrastructures, highlighting healthcare (47.4%), energy (31.6%) and manufacturing (21.1%) among the most affected sectors.
Anuj Goel, Co-founder and CEO of Cyware, added: "Even if post-incident recovery strategies have improved, it is always advisable to adopt a preventive attitude towards any attacks. To correctly analyze the threat context and assign the right priorities to proactive prevention actions, it is necessary to make information on vulnerabilities accessible to Security and Operations teams through solid management of security processes to guarantee the integrity of assets at risk".
Insights into current and future ransomware trends are also presented in the report. Specifically, malware with functionality cross-platform it has become highly sought after by hackers because it allows you to easily target multiple operating systems through a single codebase. In addition, a significant number of attacks on security providers and software code libraries have been identified, increasing the potential for damage. In the long term, after the alleged closure of prominent groups such as Conti and Dark Side, organizations should expect the emergence of new ransomware networks that may reuse or modify source code and other tools adopted by previous hackers.
The Ransomware Index Spotlight report is based on data collected from numerous sources, including proprietary data from Ivanti and CSW, public threat databases, as well as data from attack researchers and attack testing teams. For details on the full report please see link.






