Ryuk is a Windows ransomware family first observed in 2018, used in financially motivated attacks against enterprises, hospitals, municipalities, and other organizations highly sensitive to operational downtime. It encrypts files using a combination of AES and RSA, assigning individual AES keys to files, and leaves ransom notes demanding payment for recovery. Ryuk has disabled Windows System Restore to prevent recovery through restore points and has injected itself into other processes to perform file encryption using Windows memory-allocation, memory-writing, and remote-thread creation APIs.
Ryuk is commonly deployed after attackers have established access and compromised an organization's network rather than serving as the initial infection. Prominent delivery chains begin with phishing or malicious email campaigns distributing Emotet and TrickBot, followed by operator-led reconnaissance, credential theft, lateral movement, and ransomware deployment. Some Ryuk intrusions have used Zerologon, CVE-2020-1472, to obtain privileged Active Directory access and deploy ransomware across a domain within hours of the initial phishing email. These intrusion activities are distinct from the ransomware payload's own capabilities. FIN6 has been linked to Ryuk-related intrusions, while FIN7 has conducted precursor activity leading to Ryuk attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The manual discusses exploiting Zerologon (CVE-2020-1472), including an example of using Mimikatz and Zerologon together to target a domain controller.
Ryuk, which is one of the more recent families of ransomware, is notable for demanding very high ransoms of $100,000 or more.
Ryuk, which is one of the more recent families of ransomware, is notable for demanding very high ransoms of $100,000 or more.
Ryuk, which is one of the more recent families of ransomware, is notable for demanding very high ransoms of $100,000 or more.
Ryuk, which is one of the more recent families of ransomware, is notable for demanding very high ransoms of $100,000 or more.
Ryuk, which is one of the more recent families of ransomware, is notable for demanding very high ransoms of $100,000 or more.
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware.
The threat actor acting as a precursor for Maze and Ryuk ransomware attacks.
Vardanyan pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. He admitted providing initial access to corporate networks that enabled ransomware deployment.
Ryuk Ransomware: Ryuk is a highly sophisticated type of ransomware that is being used to target organizations all over the world since its discovery in August 2018.
Conti popularized the modern ransomware model with its original project, Ryuk, which was delivered via Emotet dropping Trickbot.
The TrickBot Gang... commonly leading to Conti and Ryuk ransomware attacks... other ransomware operations linked to TrickBot, such as Conti and Ryuk...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
306 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Final-stage ransomware deployed after initial access and network compromise involving Emotet, QakBot, and TrickBot. The article emphasizes targeting organizations highly sensitive to operational downtime.
Mentioned in a caption accompanying a historical interview with Pinhasi. The article provides no technical details about Ryuk and does not explicitly link it to the alleged ransom payments.
File-encrypting ransomware whose original code reportedly provided a basis for Akira. Its original developer was reportedly retained to judge Royal's competition for next-generation ransomware.
A legacy ransomware family associated with large-scale big-game-hunting attacks; the article states that no widely available free decryptor is known.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.