Vardanyan pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. He admitted providing initial access to corporate networks that enabled ransomware deployment.
Ryuk
Ryuk is a Windows ransomware family first detected in August 2018 and associated with the Russia-based cybercriminal group Wizard Spider.
Ryuk
Family profile
Ryuk is a Windows ransomware family first detected in August 2018 and associated with the Russia-based cybercriminal group Wizard Spider. It encrypts victim files, disrupts access to workstations and servers, and demands cryptocurrency payments, commonly Bitcoin, in exchange for decryption. Ryuk is known for targeted, enterprise-scale “big game hunting” attacks against organizations worldwide, including businesses, municipalities, school districts, hospitals, and other healthcare providers.
Ryuk has frequently served as the final monetization payload in intrusions involving Emotet and TrickBot. These attack chains used malicious spam and social engineering to establish infection, followed by TrickBot-assisted network compromise and subsequent ransomware deployment. Before deploying Ryuk, operators commonly performed network reconnaissance, obtained administrator credentials, and compromised domain controllers. Observed deployment methods include Group Policy, domain startup mechanisms, and PsExec. These intrusion and distribution activities should be distinguished from the ransomware payload’s file-encryption functionality.
Ryuk attacks have caused substantial operational disruption and recovery costs, including prolonged interruptions to healthcare operations and remote schooling. Confirmed victims include Universal Health Services and Baltimore County Public Schools.
Capabilities
- Extortion
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
18 named in public reportingRyuk Ransomware: Ryuk is a highly sophisticated type of ransomware that is being used to target organizations all over the world since its discovery in August 2018.
Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware.
Conti popularized the modern ransomware model with its original project, Ryuk, which was delivered via Emotet dropping Trickbot.
À l’été 2020... un incident ayant abouti six semaines après la compromission initiale au chiffrement de la victime par le rançongiciel Ryuk.
The TrickBot Gang... commonly leading to Conti and Ryuk ransomware attacks... other ransomware operations linked to TrickBot, such as Conti and Ryuk...
The threat actor behind it is known to act quickly, using the well-known post-exploitation tool Cobalt Strike to move laterally on the company network infrastructure and deploy ransomware like Ryuk or Conti as a final stage.
A recent report by Mandiant revealed that FIN12 — the group believed to be responsible for both Conti and the Ryuk ransomware operation — has managed to conduct ransomware attacks in less than 3 days...
Over the past two weeks, Ryuk, a targeted and well-planned Ransomware, has attacked various organizations worldwide.
Notably, TrickBot has been widely observed working in conjunction with Emotet to deliver Ryuk ransomware.
The Conti ransomware, or malware, first appeared in December 2019, and some security sources said it appeared to be the successor of Ryuk ransomware, which first surfaced around the middle of 2018. Ryuk originated in Russia, and appears to be controlled by a cyber crime gang known as Russian Spider.
The Conti ransomware, or malware, first appeared in December 2019, and some security sources said it appeared to be the successor of Ryuk ransomware, which first surfaced around the middle of 2018. Ryuk originated in Russia, and appears to be controlled by a cyber crime gang known as Russian Spider.
"...gain initial access to corporate networks for Ryuk, and later, Conti ransomware attacks."
"BazaLoader... subsequently installed a ransomware strain called Ryuk."
"The operators of Ryuk ransomware are at it again... There was speculation that the Ryuk actors had moved on to a rebranded version of the ransomware, called Conti."
"Some victims were infected by TrickBot starting in June 2018, then compromised by Ryuk as of August... TrickBot is the loader most responsible for the distribution of Ryuk."
"Some victims were infected by TrickBot starting in June 2018, then compromised by Ryuk as of August... TrickBot is the loader most responsible for the distribution of Ryuk."
"Some victims were infected by TrickBot starting in June 2018, then compromised by Ryuk as of August... TrickBot is the loader most responsible for the distribution of Ryuk."
Exploited software
Vulnerabilities linked to Ryuk
1 CVEsMITRE ATT&CK
Ryuk in ATT&CK
94 distinct techniquesTechniques
94 techniquesReporting
Research mentioning Ryuk
Passkey-themed social engineering leads to identity and cloud compromise - Malware News - Malware Analysis, News and Indicators
Microsoft Security Research reported cloud-account intrusions active since May 2026 in which attackers impersonate IT helpdesks through phone calls, SMS, and occasionally Microsoft Teams. The campaigns use passkey-, MFA-, and SSO-themed lures to direct users to adversary-in-the-middle phishing pages or device-code authentication flows, capturing credentials, session tokens, or attacker-authorized tokens for Microsoft cloud identities. After gaining access, the actors register attacker-controlled MFA methods, enumerate tenant resources through Microsoft Graph, and steal data from SharePoint, OneDrive, Exchange mailboxes, and attachments. Microsoft linked the initial-access ecosystem to Storm-3121, associated with ShinyHunters and Falcon extortion activity, and Storm-3032, a BlackFile splinter operating under the Helix banner; defenders should investigate identity and cloud telemetry, revoke sessions and refresh tokens, remove unauthorized authentication methods, and require phishing-resistant MFA with restrictive Conditional Access policies.
Passkey-themed social engineering leads to identity and cloud compromise | Microsoft Security Blog
Telegram shortlinks knocked offline over sanctioned VPN connection
The U.S. Treasury sanctioned First VPN Service (1VPNS), its alleged Ukrainian administrator Dmytro Rashevskyi, and Belarusian cryptor seller Yevgeniy Vladimirovich Silayev for allegedly supporting ransomware and other cybercriminal activity. Officials said 1VPNS provided anonymizing infrastructure that helped threat actors hide their identities, disguise malware, and evade detection during attacks on U.S. municipalities, hospitals, schools, businesses, and critical infrastructure providers. Treasury alleged Rashevskyi used false identities to obtain infrastructure for the service, while Silayev sold malware-obfuscation tools that made malicious code harder for defenders to detect. The sanctions, issued under Executive Order 14390 and E.O. 13694 as amended, block U.S. persons from transacting with the designated parties and mark a broader move against ransomware enablers rather than only the gangs themselves. The action was coordinated with the United Kingdom and followed a May law enforcement takedown of 1VPNS infrastructure by European agencies with FBI support. Separate reporting said blockchain tracing tied payments from ransomware groups including Anubis, Qilin, and Sinobi Group to FirstVPN, adding financial evidence that the service was used as operational infrastructure by ransomware actors.