LockBit

The LockBit ransomware gang first emerged in September 2019. LockBit, like many other ransomware gangs, leases its malicious software to third-party criminal affiliates who then receive a cut of ransoms in exchange for planting the code onto victim networks.

DarkSide

DarkSide is a ransomware-as-a-service (RaaS) outfit that provides ransomware to affiliates within its network in return for a cut of any profits made by extorting victim organizations.
DarkSide affiliates employ a double-extortion tactic, in which companies first receive a demand for payment in return for a decryption key to unlock systems infected with DarkSide ransomware. If they refuse, they are then threatened with the public release of confidential data and records stolen during initial access on a leak site.

Avaddon

Russian-speaking attackers used a ransomware variant called Avaddon.

Ransomware (target: Gyrodata)

The attacker gained access to certain systems and related data within the Gyrodata environment at various times from approximately January 16 to February 22.
The data potentially obtained by the unauthorized actor may have contained personal information of current and former Gyrodata employees, including names, addresses, dates of birth, drivers’ license numbers, Social Security numbers, passport numbers, W-2 tax forms, and information related to health plan enrollment.