Ransomware as a service operators, the main culprits behind leak sites, are exploiting more zero-day vulnerabilities. In March 2023, CLOP—the group with the third-highest number of victims on leak sites—exploited an unknown vulnerability in GoAnywhere MFT (a secure file transfer company) to spread ransomware to 48 victims.
Source: BlackFog