Naming specific ransomware groups has an awkward problem: by the time this article gets published, one of the best-known names has probably already been dismantled by an international law enforcement operation — and two new groups have likely emerged to fill the space it left behind. It's, quite literally, a global game of whack-a-mole. Even so, understanding how these groups operate as a category, rather than memorizing a list of names that expires quickly, is what actually helps a business anticipate the kind of threat it's facing.
Why the Landscape Shifts So Fast
The ransomware-as-a-service model, which we cover in detail in our guide on the topic, means "groups" aren't monolithic, stable organizations — they're criminal brands that can dissolve, regroup under another name, or fragment when their core operators get arrested. When authorities manage to dismantle a major group's infrastructure, it's common to see its affiliates simply migrate to another ransomware kit available on the underground market, within weeks.
The Patterns That Do Stay Stable
While names change, certain behavior patterns repeat consistently across the groups that have hit the region hardest:
Preference for sectors under high operational pressure. Healthcare, manufacturing, and financial services show up repeatedly among the most-targeted sectors, precisely because disrupting their operations creates faster payment pressure than in other kinds of business.
Double extortion as the standard, not the exception. The vast majority of active groups today combine encryption with prior data exfiltration, following the pattern we describe in our guide to double extortion.
Exploiting purchased access, not discovered access. A large share of successful attacks don't start with a sophisticated technical discovery by the attacker — they start with buying already-compromised credentials or access on underground markets, often originally obtained through simple phishing.
Attack timing outside local business hours. Encryption typically activates at night or on weekends, when the odds of detection and immediate response are lower.
Psychological pressure beyond the technical. Directly contacting the victim's customers or partners to pressure payment, or setting deadlines with automatic increases to the demanded amount, are increasingly common tactics.
Why Colombia and the Region Are a Consistent Target
Several factors explain why Latin America, and Colombia specifically, keep showing up on these groups' radar: accelerated digitalization of financial and government services that doesn't always come with matching speed in cybersecurity maturity, a business ecosystem with a high proportion of small businesses with limited security resources, and a perception among attackers — not always accurate, but persistent — that businesses in the region are more likely to negotiate a payment than in markets with stricter regulations around ransom payments.
What to Actually Do With This Information
Memorizing specific group names offers little real value to a business — what does offer value is understanding the behavior pattern and adjusting defenses accordingly:
Frequently asked questions
Is it worth my business tracking which ransomware groups are currently active?
There's limited value in doing this in isolation. It's more useful for a cybersecurity provider with visibility into the broader threat landscape to fold that intelligence into a continuous monitoring service, rather than each individual business trying to track it alone.
Do ransomware groups specifically target Colombian businesses, or is it random?
There's generally no country-specific focus beyond structural factors like the language of ransom notes or the type of infrastructure common in the region — victim selection tends to depend more on ease of access than on the company's nationality.
Is it true some groups avoid attacking certain sectors, like critical infrastructure?
Some groups have publicly claimed internal rules — avoiding hospitals, for example — but their affiliates' actual compliance with those rules is inconsistent in practice, and shouldn't be assumed as real protection.
How do I know if my business has already been compromised even if encryption hasn't triggered yet?
Signs like unusual network traffic, accounts acting outside their normal pattern, or unrecognized remote administration tools can indicate prior access. A proactive technical assessment is the only reliable way to confirm it.
Let's talk
Understanding the pattern behind these groups, rather than memorizing their names, is what genuinely strengthens a business's defense. At T.I. RESCUE we combine continuous monitoring with [24/7 incident response](https://tirescue.com/en/respuesta-ante-incidentes-247/) capability to act regardless of which specific group is behind an attack. Want to know how prepared your business is against this landscape? [Let's talk](https://tirescue.com/en/contacto-ti-rescue/).
Contact usYou may also like
Comments (0)
Be the first to comment.