Ryuk is a financially motivated ransomware operation associated with targeted enterprise intrusions and large-scale extortion. It is widely linked to the TrickBot ecosystem and the broader Wizard Spider cybercriminal organization, and is frequently assessed as the predecessor to, rebrand of, or closely overlapping operation with Conti. Reporting has repeatedly connected Ryuk operators with TrickBot-enabled access, shared personnel and management, and operational overlap with Conti, including common use of botnet-delivered footholds and similar intrusion tradecraft. Ryuk is known for big-game hunting against large organizations, including hospitals, major enterprises, and public-sector entities. Named victims and reporting indicate activity against organizations in the United States, France, Japan, Ireland, and the United Kingdom. Sectors directly evidenced include health care, government and public sector, industrials, and consumer discretionary, with repeated references to attacks on hospitals, government-related organizations, manufacturing and automotive firms, construction companies, and large commercial enterprises. Operationally, Ryuk has been associated with initial access obtained through malware and access brokers, especially TrickBot, Emotet, Zloader, and BazarLoader, as well as phishing-derived compromise chains. Intrusions attributed to the broader Ryuk/Conti/TrickBot cluster have featured rapid progression from initial compromise to domain-wide encryption, credential theft, privilege escalation, lateral movement, and full-network impact. TrickBot activity tied to Ryuk has included credential harvesting, theft of SSH keys and cookies, propagation through victim networks, compromise of Active Directory data, and reverse-shell access used to support ransomware deployment. Ryuk operators and affiliates have also been observed using reconnaissance tooling such as Advanced IP Scanner during targeted intrusions. The group is consistently described as conducting human-operated ransomware attacks rather than opportunistic mass encryption. Available reporting supports extortion through file encryption and ransom demands, but does not directly and consistently establish a dedicated leak-site or double-extortion model for Ryuk itself at the same confidence level as Conti. Ryuk has strong reported ties to Wizard Spider, TrickBot, and Conti. Conti is commonly described as Ryuk’s successor, and multiple analyses indicate shared developers, managers, infrastructure relationships, and funding flows between the two operations. Ryuk therefore occupies an important place in the evolution of the TrickBot-linked ransomware ecosystem as one of its most prominent early enterprise ransomware brands.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prolific ransomware group active from 2018 to 2020 that compromised hundreds of servers and workstations at US organizations and other victims, deploying Ryuk ransomware and collecting bitcoin ransom payments.
Ransomware operation active from 2018 to mid-2020 that targeted U.S. company networks across multiple sectors, including healthcare, using illegally obtained initial access to deploy ransomware and extort victims for Bitcoin payments.
A cybercrime group identified as the predecessor from which Conti emerged.
Referenced as part of the cybercrime syndicate tied to earlier BazarCall callback phishing campaigns that provided initial access for ransomware attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.