Skip to content

Ryuk

Ryuk is a Windows ransomware family first detected in August 2018 and associated with the Russia-based cybercriminal group Wizard Spider.

Ryuk

Family profile

Ryuk is a Windows ransomware family first detected in August 2018 and associated with the Russia-based cybercriminal group Wizard Spider. It encrypts victim files, disrupts access to workstations and servers, and demands cryptocurrency payments, commonly Bitcoin, in exchange for decryption. Ryuk is known for targeted, enterprise-scale “big game hunting” attacks against organizations worldwide, including businesses, municipalities, school districts, hospitals, and other healthcare providers.

Ryuk has frequently served as the final monetization payload in intrusions involving Emotet and TrickBot. These attack chains used malicious spam and social engineering to establish infection, followed by TrickBot-assisted network compromise and subsequent ransomware deployment. Before deploying Ryuk, operators commonly performed network reconnaissance, obtained administrator credentials, and compromised domain controllers. Observed deployment methods include Group Policy, domain startup mechanisms, and PsExec. These intrusion and distribution activities should be distinguished from the ransomware payload’s file-encryption functionality.

Ryuk attacks have caused substantial operational disruption and recovery costs, including prolonged interruptions to healthcare operations and remote schooling. Confirmed victims include Universal Health Services and Baltimore County Public Schools.

Capabilities

  • Extortion

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

18 named in public reporting
WIZARD SPIDER

Vardanyan pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. He admitted providing initial access to corporate networks that enabled ransomware deployment.

FIN11

Ryuk Ransomware: Ryuk is a highly sophisticated type of ransomware that is being used to target organizations all over the world since its discovery in August 2018.

FIN6

Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware.

Conti

Conti popularized the modern ransomware model with its original project, Ryuk, which was delivered via Emotet dropping Trickbot.

FIN7

À l’été 2020... un incident ayant abouti six semaines après la compromission initiale au chiffrement de la victime par le rançongiciel Ryuk.

Trickbot

The TrickBot Gang... commonly leading to Conti and Ryuk ransomware attacks... other ransomware operations linked to TrickBot, such as Conti and Ryuk...

UNC1778

The threat actor behind it is known to act quickly, using the well-known post-exploitation tool Cobalt Strike to move laterally on the company network infrastructure and deploy ransomware like Ryuk or Conti as a final stage.

fin12

A recent report by Mandiant revealed that FIN12 — the group believed to be responsible for both Conti and the Ryuk ransomware operation — has managed to conduct ransomware attacks in less than 3 days...

Lazarus

Over the past two weeks, Ryuk, a targeted and well-planned Ransomware, has attacked various organizations worldwide.

Overdose

Notably, TrickBot has been widely observed working in conjunction with Emotet to deliver Ryuk ransomware.

NC1878

The Conti ransomware, or malware, first appeared in December 2019, and some security sources said it appeared to be the successor of Ryuk ransomware, which first surfaced around the middle of 2018. Ryuk originated in Russia, and appears to be controlled by a cyber crime gang known as Russian Spider.

Russian Spider

The Conti ransomware, or malware, first appeared in December 2019, and some security sources said it appeared to be the successor of Ryuk ransomware, which first surfaced around the middle of 2018. Ryuk originated in Russia, and appears to be controlled by a cyber crime gang known as Russian Spider.

SilentRansomGroup

"...gain initial access to corporate networks for Ryuk, and later, Conti ransomware attacks."

TA800

"BazaLoader... subsequently installed a ransomware strain called Ryuk."

Ryuk

"The operators of Ryuk ransomware are at it again... There was speculation that the Ryuk actors had moved on to a rebranded version of the ransomware, called Conti."

VENOM SPIDER

"Some victims were infected by TrickBot starting in June 2018, then compromised by Ryuk as of August... TrickBot is the loader most responsible for the distribution of Ryuk."

INDRIK SPIDER

"Some victims were infected by TrickBot starting in June 2018, then compromised by Ryuk as of August... TrickBot is the loader most responsible for the distribution of Ryuk."

APT38

"Some victims were infected by TrickBot starting in June 2018, then compromised by Ryuk as of August... TrickBot is the loader most responsible for the distribution of Ryuk."

Exploited software

Vulnerabilities linked to Ryuk

1 CVEs

MITRE ATT&CK

Ryuk in ATT&CK

94 distinct techniques

Techniques

94 techniques
T1134 Access Token Manipulation T1021.002 SMB/Windows Admin Shares T1222.001 Windows Permissions T1685 Disable or Modify Tools T1016 System Network Configuration Discovery T1680 Local Storage Discovery T1490 Inhibit System Recovery T1078.002 Domain Accounts T1036 Masquerading T1614.001 System Language Discovery T1059.003 Windows Command Shell T1106 Native API T1053.005 Scheduled Task T1489 Service Stop T1057 Process Discovery T1055 Process Injection T1083 File and Directory Discovery T1036.005 Match Legitimate Resource Name or Location T1486 Data Encrypted for Impact T1027 Obfuscated Files or Information T1547.001 Registry Run Keys / Startup Folder T1205 Traffic Signaling T1657 Financial Theft T1585 Establish Accounts T1133 External Remote Services T1654 Log Enumeration T1078 Valid Accounts T1105 Ingress Tool Transfer T1190 Exploit Public-Facing Application T1041 Exfiltration Over C2 Channel T1021 Remote Services T1046 Network Service Discovery T1218 System Binary Proxy Execution T1033 System Owner/User Discovery T1598.004 Spearphishing Voice T1021.005 VNC T1070 Indicator Removal T1021.001 Remote Desktop Protocol T1570 Lateral Tool Transfer T1082 System Information Discovery T1135 Network Share Discovery T1219 Remote Access Tools T1053 Scheduled Task/Job T1566 Phishing T1059 Command and Scripting Interpreter T1566.001 Spearphishing Attachment T1018 Remote System Discovery T1059.001 PowerShell T1222 File and Directory Permissions Modification T1587.001 Malware T1047 Windows Management Instrumentation T1555 Credentials from Password Stores T1140 Deobfuscate/Decode Files or Information T1497.001 System Checks T1518.001 Security Software Discovery T1569.002 Service Execution T1573 Encrypted Channel T1546.011 Application Shimming T1537 Transfer Data to Cloud Account T1566.002 Spearphishing Link T1136.001 Local Account T1595 Active Scanning T1204 User Execution T1071 Application Layer Protocol T1027.007 Dynamic API Resolution T1560 Archive Collected Data T1070.004 File Deletion T1112 Modify Registry T1124 System Time Discovery T1497 Virtualization/Sandbox Evasion T1498 Network Denial of Service T1484 Domain or Tenant Policy Modification T1110.001 Password Guessing T1110 Brute Force T1584 Compromise Infrastructure T1087.001 Local Account T1087.002 Domain Account T1547 Boot or Logon Autostart Execution T1074 Data Staged T1055.003 Thread Execution Hijacking T1055.001 Dynamic-link Library Injection T1553.002 Code Signing T1027.002 Software Packing T1484.001 Group Policy Modification T1588.001 Malware T1583.003 Virtual Private Server T1197 BITS Jobs T1014 Rootkit T1027.014 Polymorphic Code T1020.001 Traffic Duplication T1585.002 Email Accounts T1583.002 DNS Server T1120 Peripheral Device Discovery T1482 Domain Trust Discovery

Reporting

Research mentioning Ryuk

Sep 9
Malware News

Passkey-themed social engineering leads to identity and cloud compromise - Malware News - Malware Analysis, News and Indicators

Microsoft Security Research reported cloud-account intrusions active since May 2026 in which attackers impersonate IT helpdesks through phone calls, SMS, and occasionally Microsoft Teams. The campaigns use passkey-, MFA-, and SSO-themed lures to direct users to adversary-in-the-middle phishing pages or device-code authentication flows, capturing credentials, session tokens, or attacker-authorized tokens for Microsoft cloud identities. After gaining access, the actors register attacker-controlled MFA methods, enumerate tenant resources through Microsoft Graph, and steal data from SharePoint, OneDrive, Exchange mailboxes, and attachments. Microsoft linked the initial-access ecosystem to Storm-3121, associated with ShinyHunters and Falcon extortion activity, and Storm-3032, a BlackFile splinter operating under the Helix banner; defenders should investigate identity and cloud telemetry, revoke sessions and refresh tokens, remove unauthorized authentication methods, and require phishing-resistant MFA with restrictive Conditional Access policies.

Sep 9
Microsoft General

Passkey-themed social engineering leads to identity and cloud compromise | Microsoft Security Blog

Jul 16
Register Security

Telegram shortlinks knocked offline over sanctioned VPN connection

The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.

Jul 15
Scworld

U.S. sanctions VPN provider and cryptor seller for aiding ransomware gangs | brief | SC Media

Jul 15
Xakep

Власти США наложили санкции на First VPN из-за связей с вымогателями - Хакер

Jul 14
Security Affairs

U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses

Jul 14
Cyberscoop

US sanctions First VPN and administrator for supporting ransomware | CyberScoop

Jul 14
Chainalysis

“Stern” Ransomware Operator Sanctioned by EU