The Hacker Groups Behind Today’s Biggest Cyber Threats – And How They Attack Businesses

You have probably seen the names in the news: Lazarus, Scattered Spider, Qilin. They sound like characters from a movie. But these are real groups, and they cost real companies real money — sometimes hundreds of thousands of euros in a single attack.

Small and medium businesses often think these groups only go after big banks or governments. That is a mistake. Many of these groups attack smaller companies every single day, because smaller companies are easier targets: they usually have no dedicated security team, no incident response plan, and older, unpatched systems. A twenty-person company can be just as attractive to a ransomware gang as a large corporation, sometimes more so, because the payout is still worth it while the resistance is much weaker.

News coverage does not help either. It focuses on the biggest names and the biggest headlines, which makes it easy to think this is a problem for other, bigger companies. In reality, behind every famous case there are hundreds of smaller, quieter attacks that never make the news.

This article looks at the three main types of hacker groups active right now, how they actually break into companies, and what that means for your business. No marketing scare tactics here — just a clear look at how these attacks work.

Three Types of Groups, Three Different Goals

Not all hacker groups are the same, and the difference matters for your defense strategy. Ransomware groups are criminal businesses. Their only goal is money. They lock your files, steal your data, and demand payment. If you do not pay, they threaten to publish your data online. Groups like Qilin, Akira, and LockBit work this way. They often use a “ransomware-as-a-service” model: the group builds the malware, and independent “affiliates” rent it to carry out the actual attacks and split the profit. This is why these groups can attack so many companies so fast — it is not one team, it is a whole network of smaller criminal contractors, some technical, some focused purely on negotiating the ransom.

State-sponsored groups, often called APTs, work for a government. Their goal is usually not money, but information — or in some cases, funding for a sanctioned regime. North Korea’s Lazarus Group is a well-known example, and so is Russia’s APT28 or the Chinese-linked Volt Typhoon. These groups have patience. They can sit inside a network for months, sometimes years, collecting data quietly, before anyone notices. Unlike ransomware gangs, they usually do not want to be discovered at all, because getting caught means losing access to everything they have built up.

Social engineering crews do not rely on advanced malware at all. They rely on people. Scattered Spider is the best-known example: young, English-speaking hackers who call IT help desks, pretend to be employees, and simply talk their way past security. No hacking skills required — just a convincing voice, a good story, and enough personal details about the victim to sound believable.

Understanding which type of group you might face changes how you defend yourself. A firewall does not stop a phone call to your help desk, and a strong password policy does not stop a state-sponsored group that gets in through a trusted software update. Each type of attacker calls for a different kind of defense, which is exactly why it helps to understand all three before deciding where to invest your time and budget.

Ransomware Groups: The Criminal Businesses

Ransomware is still the attack type that hits small and medium businesses hardest, and it has become a full industry. In 2025 and into 2026, groups such as Qilin became the most active ransomware operation on the planet, responsible for a large share of all ransomware attacks worldwide. Other active groups include Akira, DragonForce, Cl0p, Play, and Medusa.

These groups get in through a few well-worn paths. Many attacks start with a password that was leaked somewhere else and reused for a work account. A huge share of ransomware attacks also start with attackers exploiting a known vulnerability in a company’s remote-access equipment, such as a VPN or firewall, that was simply never updated. And of course there is the classic phishing email: a fake invoice, a fake delivery notice, a fake HR message. One click on a bad link or attachment is often all it takes.

Once inside, these groups do not encrypt your files right away. First, they explore. They look for your most important systems, your backups, and any sensitive data worth stealing. They often steal data before they encrypt anything. This gives them a second way to pressure you: even if you have good backups and can restore your systems without paying, they can still threaten to publish your customer data, contracts, or financial records online. This “double extortion” model is now standard practice, not an exception.

Smaller companies are attractive targets because they often have weaker backup systems, no dedicated security staff, and older, unpatched software. Attackers know this. Many ransomware groups specifically look for companies that are big enough to pay a meaningful ransom, but too small to have a real security team.

State-Sponsored Groups: Patient and Well-Funded

Groups like Lazarus from North Korea, APT28 from Russia, and the Chinese-linked Volt Typhoon and Salt Typhoon operate very differently from ransomware gangs. They are backed by governments, which means they have time, money, and skills that most criminal groups cannot match. A ransomware gang wants to cash out as fast as possible. A state-sponsored group can afford to wait for months before making a single move, because there is no ransom clock running and no affiliate waiting to get paid.

Instead of attacking a company directly, these groups often go after the software supply chain. They compromise a software update or a vendor that the company trusts, which means the victim essentially installs the malware themselves, believing it is a routine update. One of the largest cryptocurrency thefts in history, a 1.5-billion-dollar heist linked to North Korea, reportedly started with nothing more dramatic than a compromised software update and a single infected developer laptop. They also use spear phishing, which is different from the mass phishing emails ransomware gangs send: these messages are carefully researched and written for one specific person, often an employee with access to sensitive systems, and they can reference real projects, real colleagues, or real ongoing business deals to seem trustworthy. On top of that, state-linked groups are often the first to use newly discovered vulnerabilities in widely used software, sometimes before a patch even exists — security researchers call this a “zero-day,” because defenders have had zero days to fix it before it is already being used against them.

What also sets these groups apart is what they do once they are inside. A ransomware gang wants to be noticed, because the whole point is to get you to pay attention and pay up. A state-sponsored group wants the opposite. They move carefully, avoid triggering alarms, and often build several separate ways back into the network, so that even if one access point is discovered and closed, they can quietly return through another.

You might think, “Why would a government hacking team care about my company?” The answer is usually the supply chain. If your business supplies software, components, or services to a larger client — including government agencies, defense companies, or critical infrastructure — you can become the easier way in. Attackers go through the weakest link, and that is often a smaller supplier, not the large target itself. In practice, this means your company’s security is not only about protecting your own data. It is also part of the security of every client and partner you connect to.

Social Engineering Crews: No Malware Needed

Scattered Spider is the clearest example of this newer type of threat. This is a loosely organized group, mostly young adults in the US and UK, and they were behind major attacks on well-known hospitality and gaming companies, causing operational shutdowns that lasted for days. What makes them unusual is how little technical hacking their method actually involves. Instead of writing malware or exploiting software bugs, they exploit trust, routine, and the pressure that IT support staff are often under to solve problems quickly.

Their favorite approach is simply calling the IT help desk and pretending to be a locked-out employee asking for a password reset. With enough personal details — often gathered from LinkedIn, a company website, or an old data leak — this can sound completely convincing to an overworked support agent who just wants to help a colleague get back to work. They also use SIM swapping, where they convince a mobile carrier to move a victim’s phone number to a new SIM card, which lets them intercept one-time login codes sent by text message, effectively bypassing a security step that many companies still rely on as their main protection. And they build fake login pages that send employees a link to a page that looks identical to the real Microsoft or Okta login screen, simply collecting the password when it is typed in, sometimes even in real time, so they can use it before the employee even realizes something was wrong.

What makes this group particularly hard to defend against is their patience with people, not systems. They will call more than once if the first attempt fails, try a different employee, or claim urgency — “I’m about to miss a client deadline” — to push past normal caution. They study a company’s structure in advance, sometimes learning who reports to whom, which makes their story sound even more credible.

Multi-factor authentication is good advice, but it is not a magic shield. If an attacker can talk your help desk into resetting a password or approving a login request, technical defenses do not help much, because from the system’s point of view, this looks like a normal, authorized action. This is a people problem, not a software problem, and it needs a people-focused solution: clear verification procedures for password resets that do not rely on the caller simply sounding convincing, and staff who are trained and empowered to say no, even under pressure, even when someone claims it is urgent.

What This Actually Means for Your Company

None of this is meant to scare you into buying a specific tool — plenty of vendors will happily do that for you, usually with a slide showing a hacker in a black hoodie and a number that is supposed to make you panic. The honest picture is simpler and, in a way, more reassuring: you do not need to defend against every possible attack technique. You need to close the handful of doors that these groups actually use, over and over again.

Most attacks do not start with brilliant hacking. They start with a reused password, an unpatched VPN, or a convincing phone call, and basic hygiene stops far more attacks than any advanced tool ever will. A company that patches its systems regularly, requires unique passwords, and has a clear process for verifying identity already blocks the majority of what ransomware gangs, state-sponsored groups, and social engineering crews rely on.

Backups are not enough anymore either. For years, “just have good backups” was considered solid ransomware protection, and it was — as long as attackers only encrypted your files. Now that data theft usually happens before encryption, a good backup protects your operations, but not your reputation or your customer data. You can restore every file perfectly and still end up with your contracts, employee records, or client data published online.

“Do we have backups?” For many organizations, this question effectively ends the cybersecurity discussion. Once the answer is “yes,” the topic is considered resolved. In reality, this assumption has become one of the most dangerous blind spots in modern IT environments. This article examines why backups fail in practice and what separates a backup that merely exists from one that actually protects the business.

Your suppliers and vendors are also part of your risk, whether you think about it that way or not. If you connect to a larger client’s systems, or use third-party software, you are part of someone else’s supply chain, and a target because of it. This works in both directions: your own vendors and software providers are part of your risk too, which is why it is worth asking what security standards they actually follow, not just assuming they do.

Finally, your help desk needs a real verification process, because anyone can call and claim to be a locked-out employee. Your process should not rely on trust or a convincing voice alone — it should rely on a step that cannot be talked around, such as a callback to a known number or a pre-agreed verification question.

None of these measures are exotic or expensive. They are basic discipline, applied consistently, which is exactly what most attackers are counting on you not to have.

The term “Putin Bears” is often used as a general label for different Russian hacker groups. But what is really behind it? In this video, I explain how a russian hacker group operates, how these groups are structured, and what makes their attacks so effective. Do you prefer reading? Russian Hacker Group Explained: How the “Putin Bears” Really Operate

 

Conclusion: How well-known ransomware groups attack small businesses

By now it should be clear that there is no single trick that stops every attack. But understanding how ransomware groups attack small businesses is the first real step toward defending against them. These groups do not pick their targets by chance, and they do not need advanced skills to get in. A reused password, an unpatched VPN, or one convincing phishing email is usually enough. Once they are inside, the pattern is almost always the same: explore the network, find the backups, steal the data, and only then encrypt the files.

Small businesses are not attacked less often than large companies — they are often attacked more, simply because they are easier to break into and less likely to notice in time. The good news is that the same basic habits that stop most of these attacks are not expensive or complicated: patch your systems, use unique passwords with multi-factor authentication, train your staff to question unexpected requests, and test your backups before you need them. Ransomware groups will keep changing names and tactics, but the door they walk through rarely does.

I also recomond to read the following article

Cybersecurity Is Not Dead: Why Small Businesses Need Security Expertise More Than Ever

How Hackers Really Think – And Why Many Companies Misunderstand Their Approach

How Hackers Target Small Businesses Without Advanced Technology

How to Stop Ransomware on Your Devices: A Practical Guide for Small Businesses

Organized cybercrime via Telegram: how a mechanical engineer was hacked

When AI Turns Rogue: How attackers use DeepSeek for hacking

Cordula Boeck
Cordula Boeck

Hello, I'm Cordula, founder of CyberSecureGuard. The WannaCry ransomware attack sparked my interest in cybersecurity and showed me how quickly cyber threats can affect businesses. Today, I help SMEs stay safe online—no tech jargon, just practical advice that works. Through CyberSecureGuard, I share simple, real-world guidance to help protect your business from cyber threats.

Articles: 152