Ryuk
Malware⚠️ Overview
Ryuk is a human-operated ransomware family first identified in August 2018 by cybersecurity firm Check Point, linked to the threat group Wizard Spider (also tracked as UNC1878, Grim Spider, and FIN12). It belongs to the ransomware category and is delivered as a secondary payload after initial access is established via TrickBot or Emotet infections, often targeting enterprise networks through phishing or compromised RDP sessions. Unlike automated ransomware, Ryuk involves manual hands-on-keyboard attacks to maximize ransom payments.
🔧 Technical Capabilities
Ryuk propagates laterally using PowerShell scripts and PsExec, deploying its payload via scheduled tasks, Windows Service control, and DLL side-loading techniques. It employs a C2 infrastructure that uses hardcoded IP addresses and domain generation algorithms (DGAs) to retrieve encryption keys, and it leverages the open-source AES and RSA-4096 encryption algorithms to encrypt files, appending the .ryk extension. Persistence is achieved through registry run keys and scheduled tasks, while evasion excludes certain file paths (e.g., Windows system directories) and uses process hollowing to bypass security tools. Ryuk terminates over 40 services (including database and backup applications) to prevent recovery.
📜 History & Notable Incidents
Ryuk’s first major campaign in late 2018 targeted US hospitals and local governments, with a notable attack on the city of Baltimore in May 2019 causing estimated damages of $18 million. In 2020, Ryuk was used in attacks on Universal Health Services (UHS) and Emsisoft reported that Ryuk victims paid over $61 million in ransoms during 2019–2020. Law enforcement actions include the 2021 seizure of TrickBot infrastructure by Europol and the FBI, which indirectly disrupted Ryuk delivery chains. No CVEs are directly associated with Ryuk itself, but it exploits vulnerabilities in RDP (CVE-2019-0708 BlueKeep) and SMB (EternalBlue) for initial access.
🔍 Detection Indicators
Known file hashes include SHA256: 5ab5f8b8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8c8 (placeholder; actual IOCs are available in FireEye and CrowdStrike reports). Behavioral signatures include rapid deletion of Volume Shadow Copies via vssadmin.exe delete shadows /all /quiet and execution of schtasks.exe to create persistence tasks. Network IOCs include connections to IPs on port 443 with TLS certificates issued to "Ryuk" or non-standard CAs. Registry keys created under HKEY_CURRENT_USERSoftwareRyuk and mutex names like RyukMutex_ are common.
☠️ Risk & Impact
Ryuk causes complete data encryption across entire networks, often exfiltrating sensitive data before encryption (though data exfiltration is not its primary function). Financial losses from Ryuk attacks exceed $150 million globally, with healthcare, manufacturing, and government sectors most affected. The ransomware typically demands ransoms between $15,000 and $1.2 million in Bitcoin, with average payments rising to over $500,000 in 2020 per incident.
🛡️ Mitigation
Recommended defensive measures include disabling RDP where unnecessary, implementing network segmentation, and maintaining offline backups. Detection rules are provided in MITRE ATT&CK technique T1486 (Data Encrypted for Impact) and Splunk ES content libraries, while tools like CrowdStrike Falcon and Microsoft Defender for Endpoint can block Ryuk at the execution stage using behavioral analytics.
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.