Ryuk is a financially motivated ransomware operation associated with high-impact, enterprise-focused extortion campaigns active primarily from 2018 through mid-2020. It is widely characterized as a Russian-linked cybercrime threat and is commonly associated with big-game hunting against large organizations, including healthcare, education, government, manufacturing, and other enterprise sectors. Ryuk became notable for disruptive intrusions, rapid domain-wide deployment, and multimillion-dollar ransom demands. Ryuk intrusions commonly relied on access provided by other criminal malware ecosystems and affiliates rather than purely self-contained initial compromise. Reported access paths and precursor activity include phishing, malspam, compromised remote access, and infections involving Emotet, TrickBot, BazarLoader, BazarCall, and Buer Loader. Operators and affiliates frequently conducted hands-on-keyboard post-compromise activity before encryption, including Active Directory enumeration, credential theft, Kerberoasting attempts, privilege escalation, lateral movement, and targeting of backup infrastructure. Observed Ryuk tradecraft includes extensive use of native administrative tooling and common offensive utilities for reconnaissance and propagation. Reported techniques include querying domain trusts and privileged groups, using AdFind and BloodHound or SharpHound for directory mapping, deploying Cobalt Strike for command and control and lateral movement, abusing WMI, SMB, RDP, and remote service execution, disabling or modifying security tools, deleting shadow copies, stopping backup and database services, and changing file permissions to facilitate encryption. Ryuk operators have also been linked to the use of tools such as GMER to identify and terminate hidden processes and antivirus components. Ryuk is closely tied to the broader TrickBot cybercrime ecosystem, and many researchers assess that the later Conti ransomware syndicate emerged from or succeeded the Ryuk operation. Multiple former Ryuk participants are reported to have transitioned into Conti, and leaked Conti materials indicated procedural continuity with Ryuk-era playbooks. Ryuk-associated tradecraft has also been linked historically to BazarCall-style social engineering activity that later appeared in post-Conti extortion operations. The group’s operational model appears to have involved multiple specialized roles, including initial access brokers and deployment operators. Public criminal cases have documented individuals pleading guilty for providing access to victim networks and participating in Ryuk deployments against U.S. organizations. Ryuk has also been linked to laundering and financial facilitation networks used by Russian-speaking cybercriminals. Ryuk is commonly referenced by the aliases Ryuk actors, Ryuk gang, Ryuk operators, and Ryuk ransomware group. Its significance in ransomware history stems from its role in industrializing targeted enterprise ransomware operations and serving as a precursor to later large-scale Russian-speaking extortion syndicates, especially Conti.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation active from 2018 to mid-2020 that targeted U.S. company networks across multiple sectors, including healthcare, using illegally obtained initial access to deploy ransomware and extort victims for Bitcoin payments.
A cybercrime group identified as the predecessor from which Conti emerged.
Referenced as part of the cybercrime syndicate tied to earlier BazarCall callback phishing campaigns that provided initial access for ransomware attacks.
Referenced as a ransomware group associated with BazarCall callback phishing operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.