Automatically translated.View original post

84% of ransomware often works civil service periods.

84% of ransomware is often worked during government hours and business hours, according to researchers.

According to a report by the website Security Affairs, a study of the work of hackers behind ransomware by the Ransomnews Research Team, with a study of over 16,699 websites for posting stolen information from victims' organizations (Leak Post) posted on underground websites. By the craft of up to 200 ransomware groups, many interesting figures were found, such as

Most ransomware groups work during standard Office Hours in continental Europe, particularly during October, with up to 611 posts in 2024 and 1,029 posts in 2025.

Once delved into the Leak Post period, it was found that Monday averaged 3,080 posts, Tuesday 3,073 posts, but Sunday had only 1,189 posts. Only out of the 24-month period of maternity data was collected.

During the posting period, it was detected that 50% of the 16,699 posts were posted between 15: 00 and 22: 59 UTC Standard Time, compared to 11: 00 and 18: 00 Eastern American Time and 16: 00 and 23: 00 Central European Time.

The interesting thing is that during this time, at 4: 00 p.m., according to UTC, there were only 215 posts during the two-year period of data collection.

There are also statistics of new and old ransomware that began to play a major role after the famous ransomware RansomHub was subdued in 2025:

Ransomware group The Gentlemen began posting information that came out during September 2025, which counted 408 victims of the attack over a period of 246 days.

Instead, Qilin ransomware has become a large group, capable of killing 1,690 victims over a period of 731 days, with an average of 2.3 stolen data posts per day.

The Akira ransomware group came 2nd with up to 1,124 victims.

The RansomHub group was able to take down 801 victims over 322 days.

The Safepay group, which started in November 2024, managed to take 475 victims.

# Trending # Lemon 8 Howtoo # lemon 8 diary # Ransomware # freedomhack

6/25 Edited to

... Read moreจากประสบการณ์ในการติดตามเหตุการณ์แรนซัมแวร์ ผมเห็นว่าการที่กลุ่มแรนซัมแวร์ส่วนใหญ่มักทำงานในช่วงเวลาราชการนั้นมีเหตุผลหลายประการ ประการแรกคือช่วงเวลานี้เป็นเวลาทำงานขององค์กรต่างๆ ที่มีการใช้งานระบบ IT อย่างต่อเนื่อง ทำให้การโจมตีสามารถสอดคล้องกับช่วงเวลาที่มีความเคลื่อนไหวของระบบ การตรวจจับหรือแจ้งเตือนอาจจะช้ากว่าปกติเนื่องจากทรัพยากรฝ่าย IT อาจกำลังจัดการงานอื่นๆ นอกจากนี้กลุ่มแรนซัมแวร์ยังเลือกช่วงเวลาทำงานในโซนเวลายุโรปกลางและอเมริกาตะวันออก ซึ่งสอดคล้องกับเวลาทำการของธุรกิจขนาดใหญ่ทั่วโลก จึงช่วยเพิ่มโอกาสสำเร็จในการลอบขโมยข้อมูลและเรียกค่าไถ่ได้มากขึ้น ส่วนสถิติที่พบว่าช่วงเวลาประมาณ 16:00 น. UTC มีการโพสต์ข้อมูลรั่วไหลน้อยมากนั้น อาจสะท้อนถึงช่วงเวลาที่นักแฮกเกอร์เองก็มีการพักผ่อนหรือกำลังวางแผนขั้นตอนถัดไป ผมเห็นว่าการวิเคราะห์เวลาการทำงานของกลุ่มแรนซัมแวร์เป็นกุญแจสำคัญที่ช่วยให้องค์กรต่างๆ วางมาตรการป้องกันให้เหมาะสม เช่น การเพิ่มความเข้มงวดในการตรวจสอบระบบช่วงเวลาทำการ และเตรียมความพร้อมของการตอบสนองเหตุการณ์นอกเวลางาน สุดท้ายนี้ เทรนด์กลุ่มแรนซัมแวร์ที่มาแทนกลุ่มเดิมๆ อย่าง Qilin ที่มีเหยื่อมากถึงกว่า 1,600 ราย ในช่วงเวลา 2 ปี นับเป็นสัญญาณเตือนที่องค์กรทุกระดับควรให้ความสำคัญกับการเสริมความปลอดภัยไซเบอร์อย่างต่อเนื่อง ทั้งการฝึกอบรมพนักงาน การอัปเดตซอฟต์แวร์ และการเฝ้าระวังช่องโหว่ต่างๆ เพื่อป้องกันการถูกโจมตีจากกลุ่มแรนซัมแวร์ที่มีความชำนาญและใช้วิธีโจมตีที่ซับซ้อนมากขึ้นเรื่อยๆ