{"id":6723,"date":"2024-02-16T17:38:26","date_gmt":"2024-02-17T01:38:26","guid":{"rendered":"https:\/\/www.alvaka.net\/beta\/?p=6723"},"modified":"2026-09-27T19:15:04","modified_gmt":"2026-09-28T02:15:04","slug":"which-ransomware-groups-should-we-watch-in-2024","status":"publish","type":"post","link":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/","title":{"rendered":"Which Ransomware Groups Should We Watch For in 2024?"},"content":{"rendered":"<div class=\"wpb_text_column wpb_content_element\">\n<div class=\"wpb_wrapper\">\n<h3>3 Most Active Ransomware Groups in 2023<\/h3>\n<p>The three most active ransomware gangs in 2023 were LockBit 3.0, <strong><a href=\"https:\/\/www.alvaka.net\/alphv-blackcat-ransomware-recovery-services\/\" target=\"_blank\" rel=\"noopener\">Alphv<\/a><\/strong>, and <strong><a href=\"https:\/\/www.alvaka.net\/clop-ransomware-recovery-services\/\" target=\"_blank\" rel=\"noopener\">Cl0p<\/a><\/strong>. While these three were the primary contributors to the sharp increase in ransomware attacks in 2023, a significant number of attacks also originated from <strong><a href=\"https:\/\/www.alvaka.net\/8base-ransomware-recovery\/\" target=\"_blank\" rel=\"noopener\">8Base<\/a><\/strong>, 3AM, <strong><a href=\"https:\/\/www.alvaka.net\/akira-ransomware-recovery-services\/\" target=\"_blank\" rel=\"noopener\">Akira<\/a><\/strong>, Play, and <strong><a href=\"https:\/\/www.alvaka.net\/rhysida-ransomware-recovery-services\/\" target=\"_blank\" rel=\"noopener\">Rhysida<\/a><\/strong>, ransomware groups. In 2023, the ransomware industry witnessed a startling surge, experiencing a 55.5% increase in global victims, totaling an astonishing 4,368 cases. The trajectory showed explosive growth in 2021, a momentary dip in 2022, and yet another surge in 2023. LockBit retained its top position, securing 1047 victims through notable attacks on <strong><a href=\"https:\/\/www.cnbc.com\/2023\/11\/01\/boeing-investigating-cyber-incident-affecting-parts-business.html\" target=\"_blank\" rel=\"noopener\">Boeing<\/a><\/strong>, <strong><a href=\"https:\/\/www.alvaka.net\/lockbit-3-0-hits-japans-largest-trading-port\/\" target=\"_blank\" rel=\"noopener\">Nagoya Harbor<\/a><\/strong>, and <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/lockbit-ransomware-gang-claims-royal-mail-cyberattack\/\" target=\"_blank\" rel=\"noopener\">the Royal Mail<\/a><\/strong>. In contrast, Alphv and Cl0p achieved comparatively less success, with 445 and 384 victims, respectively. In the second quarter of 2023, there were 1386 newly documented ransomware cases, marking a 67% increase in victims compared to the first quarter. Quarter 3 surpassed this figure even further, reaching a total of 1420 cases.<\/p>\n<h3>3 New Ransomware Groups in 2024<\/h3>\n<p>Each ransomware group exhibits distinct characteristics, and the extent of the threat posed by a particular ransomware operation to legitimate companies can vary significantly. The three new ransomware gangs to look out for in 2024 are Akira, Rhysida, and 3AM.<\/p>\n<h4><strong>The Akira Group<\/strong><\/h4>\n<p>Making its debut in March 2023, Akira Ransomware swiftly gained notoriety through its unique 1980s-themed website and substantial ransom demands, ranging from $200,000 to $4 million. The group strategically focuses on various sectors, particularly healthcare, finance, real estate, and manufacturing, boasting over 81 claimed victims to date. Akira stands out for its proficiency in targeting both Windows and Linux systems. Notably, potential connections with the infamous Conti ransomware group have been suggested due to shared elements in their code and cryptocurrency wallets. Akira operates as a ransomware-as-a-service, impacting both Windows and Linux systems. The group utilizes its official data leak site (DLS) to disclose information about victims and provide updates on their activities. While their primary focus is on the United States, they also target the United Kingdom, Australia, and various other countries. Employing a double-extortion strategy, Akira infiltrates and encrypts data, compelling victims to pay two separate ransoms for regaining access and file restoration. In nearly all instances of intrusion, Akira leverages compromised credentials as the initial entry point into the victim\u2019s environment. Notably, a significant number of targeted organizations failed to implement multi-factor authentication (MFA) for their VPNs. Although the exact source of these compromised credentials remains uncertain, there\u2019s a possibility that the threat actors obtained access or credentials from the dark web.<\/p>\n<h4><strong>Rhysida Ransomware<\/strong><\/h4>\n<p>Since its establishment in May 2023, Rhysida ransomware has swiftly gained prominence, notably for its bold attacks on governmental entities such as the <strong><a href=\"https:\/\/www.alvaka.net\/what-is-the-black-basta-buster\/\" target=\"_blank\" rel=\"noopener\">Chilean Army<\/a><\/strong>, healthcare entities such as Prospect Medical Holdings, and high-profile entities such as the British Library and Insomniac Games. Initially, the Rhysida Group emerged as a \u201cCybersecurity Team,\u201d establishing a victim support chat portal on their website with the intention of targeting their systems and finding out their vulnerabilities.<\/p>\n<p>Operating with a double-extortion approach, Rhysida not only encrypts victims\u2019 files but also pilfers sensitive data, subsequently applying pressure by threatening public data leaks unless ransoms are promptly settled. Speculation suggests that Rhysida may have affiliations or shared members with older malware groups, providing it with a distinct advantage in terms of experience and reach. The heightened risk posed by Rhysida stems from its inclination to target unencrypted organizational data. Upon infiltrating a system, Rhysida quickly restricts access to sensitive files and data. Rhysida distinguishes itself through its inventive ransom demands. Organizations, particularly in North and South America, have encountered a distinctive PDF ransom note, a departure from the usual TXT or HTML formats. While seemingly subtle, this nuance could serve as a precedent for upcoming malware strains to employ similar evasion techniques.<\/p>\n<h4><strong>3AM Ransomware<\/strong><\/h4>\n<p>One of the newer ransomware groups is a strain called 3AM. Not much is known about this group and in 2023, it only managed to impact about 20 victims residing in the US. Emerging ransomware families come and go, with many failing to gain substantial traction. Nevertheless, the utilization of <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-use-new-3am-ransomware-to-save-failed-lockbit-attack\/\" target=\"_blank\" rel=\"noopener\">3AM as a fallback by a LockBit<\/a><\/strong> affiliate hints at potential interest from attackers, raising the possibility of its resurgence in the future. Notably, 3AM seems to be an entirely novel malware family. Upon infiltrating a system, it consistently follows a specific sequence: first attempting to halt multiple services on the compromised computer before initiating the file encryption process. Following encryption, it endeavors to erase VSS copies.<\/p>\n<p>3AM distinguishes itself from other ransomware through the use of outdated methods. Many cybersecurity analysts speculate that using older scripts and technology may obscure the bad actors from detection by modern security tools. However, employing outdated methods and technology results in vulnerabilities, potential countermeasures, and likely sabotage. The decision by the 3AM ransomware group to utilize an outdated PHP script highlights the unpredictable nature of cybercriminals. This emphasizes the necessity for organizations to stay vigilant and embrace a comprehensive security approach, acknowledging that threats can arise from both modern and antiquated technologies.<\/p>\n<\/div>\n<\/div>\n<div class=\"wpb_text_column wpb_content_element\">\n<div class=\"wpb_wrapper\">\n<p><strong>Click <a href=\"https:\/\/www.alvaka.net\/ransomware-prevention\/\">HERE<\/a> to learn more about Ransomware Prevention! We are available 24\u00d77 to assist you with any of your ransomware needs.<\/strong><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>3 Most Active Ransomware Groups in 2023 The three most active ransomware gangs in 2023 were LockBit 3.0, Alphv, and Cl0p. While these three were the primary contributors to the sharp increase in ransomware attacks in 2023, a significant number of attacks also originated from 8Base, 3AM, Akira, Play, and Rhysida, ransomware groups. In 2023, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":714,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"disabled","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[1],"tags":[19,24],"class_list":["post-6723","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles","tag-cybersecurity","tag-ransomware"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Which Ransomware Groups Should We Watch For in 2024? - Alvaka<\/title>\n<meta name=\"description\" content=\"Each ransomware group exhibits distinct characteristics. The three new ransomware gangs to look out for in 2024 are Akira, Rhysida, and 3AM.\u00a0\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Which Ransomware Groups Should We Watch For in 2024? - Alvaka\" \/>\n<meta property=\"og:description\" content=\"Each ransomware group exhibits distinct characteristics. The three new ransomware gangs to look out for in 2024 are Akira, Rhysida, and 3AM.\u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/\" \/>\n<meta property=\"og:site_name\" content=\"Alvaka Website\" \/>\n<meta property=\"article:published_time\" content=\"2024-02-17T01:38:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-28T02:15:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.alvaka.net\/beta\/wp-content\/uploads\/2026\/06\/Featured-Image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"830\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Alvaka Team\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alvaka Team\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/\"},\"author\":{\"name\":\"Alvaka Team\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#\\\/schema\\\/person\\\/4629df62c1f239cb0909896caaf55bb7\"},\"headline\":\"Which Ransomware Groups Should We Watch For in 2024?\",\"datePublished\":\"2024-02-17T01:38:26+00:00\",\"dateModified\":\"2026-09-28T02:15:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/\"},\"wordCount\":849,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Featured-Image.jpg\",\"keywords\":[\"Cybersecurity\",\"Ransomware\"],\"articleSection\":[\"Articles\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/\",\"url\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/\",\"name\":\"Which Ransomware Groups Should We Watch For in 2024? - Alvaka\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Featured-Image.jpg\",\"datePublished\":\"2024-02-17T01:38:26+00:00\",\"dateModified\":\"2026-09-28T02:15:04+00:00\",\"description\":\"Each ransomware group exhibits distinct characteristics. The three new ransomware gangs to look out for in 2024 are Akira, Rhysida, and 3AM.\u00a0\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Featured-Image.jpg\",\"contentUrl\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Featured-Image.jpg\",\"width\":1600,\"height\":830},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/which-ransomware-groups-should-we-watch-in-2024\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Which Ransomware Groups Should We Watch For in 2024?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#website\",\"url\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/\",\"name\":\"Alvaka Website\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#organization\",\"name\":\"Alvaka Website\",\"url\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Alvaka-logo-white-2.png\",\"contentUrl\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Alvaka-logo-white-2.png\",\"width\":209,\"height\":48,\"caption\":\"Alvaka Website\"},\"image\":{\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/#\\\/schema\\\/person\\\/4629df62c1f239cb0909896caaf55bb7\",\"name\":\"Alvaka Team\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ff0f7229721f07e2758536c92b69a58cb8fa511bd275a0e56d5a4b6c619a7a58?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ff0f7229721f07e2758536c92b69a58cb8fa511bd275a0e56d5a4b6c619a7a58?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ff0f7229721f07e2758536c92b69a58cb8fa511bd275a0e56d5a4b6c619a7a58?s=96&d=mm&r=g\",\"caption\":\"Alvaka Team\"},\"sameAs\":[\"https:\\\/\\\/alvaka.net\\\/beta\"],\"url\":\"https:\\\/\\\/www.alvaka.net\\\/beta\\\/author\\\/alvtlgclients-com\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Which Ransomware Groups Should We Watch For in 2024? - Alvaka","description":"Each ransomware group exhibits distinct characteristics. The three new ransomware gangs to look out for in 2024 are Akira, Rhysida, and 3AM.\u00a0","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Which Ransomware Groups Should We Watch For in 2024? - Alvaka","og_description":"Each ransomware group exhibits distinct characteristics. The three new ransomware gangs to look out for in 2024 are Akira, Rhysida, and 3AM.\u00a0","og_url":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/","og_site_name":"Alvaka Website","article_published_time":"2024-02-17T01:38:26+00:00","article_modified_time":"2026-09-28T02:15:04+00:00","og_image":[{"width":1600,"height":830,"url":"https:\/\/www.alvaka.net\/beta\/wp-content\/uploads\/2026\/06\/Featured-Image.jpg","type":"image\/jpeg"}],"author":"Alvaka Team","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alvaka Team","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/#article","isPartOf":{"@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/"},"author":{"name":"Alvaka Team","@id":"https:\/\/www.alvaka.net\/beta\/#\/schema\/person\/4629df62c1f239cb0909896caaf55bb7"},"headline":"Which Ransomware Groups Should We Watch For in 2024?","datePublished":"2024-02-17T01:38:26+00:00","dateModified":"2026-09-28T02:15:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/"},"wordCount":849,"commentCount":0,"publisher":{"@id":"https:\/\/www.alvaka.net\/beta\/#organization"},"image":{"@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/#primaryimage"},"thumbnailUrl":"https:\/\/www.alvaka.net\/beta\/wp-content\/uploads\/2026\/06\/Featured-Image.jpg","keywords":["Cybersecurity","Ransomware"],"articleSection":["Articles"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/","url":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/","name":"Which Ransomware Groups Should We Watch For in 2024? - Alvaka","isPartOf":{"@id":"https:\/\/www.alvaka.net\/beta\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/#primaryimage"},"image":{"@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/#primaryimage"},"thumbnailUrl":"https:\/\/www.alvaka.net\/beta\/wp-content\/uploads\/2026\/06\/Featured-Image.jpg","datePublished":"2024-02-17T01:38:26+00:00","dateModified":"2026-09-28T02:15:04+00:00","description":"Each ransomware group exhibits distinct characteristics. The three new ransomware gangs to look out for in 2024 are Akira, Rhysida, and 3AM.\u00a0","breadcrumb":{"@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/#primaryimage","url":"https:\/\/www.alvaka.net\/beta\/wp-content\/uploads\/2026\/06\/Featured-Image.jpg","contentUrl":"https:\/\/www.alvaka.net\/beta\/wp-content\/uploads\/2026\/06\/Featured-Image.jpg","width":1600,"height":830},{"@type":"BreadcrumbList","@id":"https:\/\/www.alvaka.net\/beta\/which-ransomware-groups-should-we-watch-in-2024\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.alvaka.net\/beta\/"},{"@type":"ListItem","position":2,"name":"Which Ransomware Groups Should We Watch For in 2024?"}]},{"@type":"WebSite","@id":"https:\/\/www.alvaka.net\/beta\/#website","url":"https:\/\/www.alvaka.net\/beta\/","name":"Alvaka Website","description":"","publisher":{"@id":"https:\/\/www.alvaka.net\/beta\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.alvaka.net\/beta\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.alvaka.net\/beta\/#organization","name":"Alvaka Website","url":"https:\/\/www.alvaka.net\/beta\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.alvaka.net\/beta\/#\/schema\/logo\/image\/","url":"https:\/\/www.alvaka.net\/beta\/wp-content\/uploads\/2026\/06\/Alvaka-logo-white-2.png","contentUrl":"https:\/\/www.alvaka.net\/beta\/wp-content\/uploads\/2026\/06\/Alvaka-logo-white-2.png","width":209,"height":48,"caption":"Alvaka Website"},"image":{"@id":"https:\/\/www.alvaka.net\/beta\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.alvaka.net\/beta\/#\/schema\/person\/4629df62c1f239cb0909896caaf55bb7","name":"Alvaka Team","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ff0f7229721f07e2758536c92b69a58cb8fa511bd275a0e56d5a4b6c619a7a58?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ff0f7229721f07e2758536c92b69a58cb8fa511bd275a0e56d5a4b6c619a7a58?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ff0f7229721f07e2758536c92b69a58cb8fa511bd275a0e56d5a4b6c619a7a58?s=96&d=mm&r=g","caption":"Alvaka Team"},"sameAs":["https:\/\/alvaka.net\/beta"],"url":"https:\/\/www.alvaka.net\/beta\/author\/alvtlgclients-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/posts\/6723","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/comments?post=6723"}],"version-history":[{"count":1,"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/posts\/6723\/revisions"}],"predecessor-version":[{"id":6724,"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/posts\/6723\/revisions\/6724"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/media\/714"}],"wp:attachment":[{"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/media?parent=6723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/categories?post=6723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.alvaka.net\/beta\/wp-json\/wp\/v2\/tags?post=6723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}