The number of ransomware attacks[1] which threaten to leak stolen data if the victim doesn't pay a ransom to get their encrypted files and servers back is growing – and this is being reflected in the changing nature of the cyber criminal market.

Analysis by cybersecurity researchers at Digital Shadows[2] found that over the last three months – between July and September - 80 percent of ransomware attacks combined with data dumps were associated with four families of ransomware – Maze[3], Sodinokibi[4], Conti[5] and Netwalker.

The period from April to June saw just three ransomware families account for 80 percent of alerts – DoppelPaymer, Maze and Sodinokibi.

The way DoppelPayer has dropped off and how Conti and NetWalker have suddenly emerged some of the most prolific threats shows how the ransomware space continues to evolve, partly because of how successful it has already become for the crooks behind it.

Maze was the first major family of ransomware to add threats of data breaches to their ransom demands and other ransomware operators have taken note – and stolen the additional extortion tactic.

"There is an inherent competitive nature that has befallen the ransomware landscape. The saturated ransomware market pushes ransomware developers to cut through the noise and gain the best ransomware title," Alec Alvarado, cyber threat intelligence analyst at Digital Shadows told ZDNet.

"This title drives more affiliates to carry out their work and, thus, more successful attacks to reach their goal: to make as much money as possible".

Indeed, DoppelPaymer's activity has dropped over the last few months – although it still remains active[6] - enabling Conti and NetWalker to grab a larger slice of the pie.

SEE: A winning

Read more from our friends at ZDNet