Ryuk is a Windows ransomware family first observed in 2018 that became one of the most prominent big-game ransomware operations active through roughly mid-2020. It was used to encrypt systems across a wide range of sectors, including enterprises, municipalities, schools, critical infrastructure, and healthcare, and was associated with numerous high-impact intrusions in 2019 and 2020. Ryuk operators demanded Bitcoin payments in exchange for decryption and were linked to substantial ransom revenue.
Ryuk commonly appeared late in multi-stage intrusion chains rather than as a standalone initial-access mechanism. Reported campaigns tied Ryuk deployment to upstream malware ecosystems including TrickBot, BazarLoader, and, more broadly, Emotet-enabled access. Observed intrusion sequences included phishing-delivered loader activity followed by internal reconnaissance, Active Directory and registry queries, and then ransomware deployment across large numbers of servers and workstations. Court cases and sanctions reporting also tie Ryuk to the broader TrickBot cybercrime ecosystem, and many Ryuk-associated actors later transitioned into or were closely linked with the Conti operation.
Operationally, Ryuk has been documented performing pre-encryption actions intended to maximize impact and hinder recovery. These behaviors include terminating services and processes prior to encryption, using batch-script-driven tradecraft in some deployments, and deleting or forcing deletion of Volume Shadow Copies to inhibit restoration. Ryuk also performs locale-based execution checks and has been observed terminating execution on systems configured for certain CIS-region languages, a behavior consistent with geofencing and operator risk reduction. Ryuk intrusions frequently involved hands-on-keyboard activity after initial compromise, with attackers using compromised access to move through victim environments and deploy the ransomware broadly.
Ryuk is widely regarded as a foundational ransomware lineage in the TrickBot-centered cybercrime ecosystem. Its operators and affiliates were later connected to successor or related operations including Conti, and its tradecraft influenced later ransomware playbooks built around structured intrusion workflows, enterprise-scale deployment, and disruptive encryption for extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Privileges have been escalated using Mimikatz, Rubeus4 [13], or by exploiting a Zerologon vulnerability (CVE-2020-1472) [26]."
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Example 8 — Pivot from malware to infrastructure You found a Ryuk ransomware sample (SHA256 hash).
The Conti ransomware, or malware, first appeared in December 2019, and some security sources said it appeared to be the successor of Ryuk ransomware, which first surfaced around the middle of 2018. Ryuk originated in Russia, and appears to be controlled by a cyber crime gang known as Russian Spider.
The Conti ransomware, or malware, first appeared in December 2019, and some security sources said it appeared to be the successor of Ryuk ransomware, which first surfaced around the middle of 2018. Ryuk originated in Russia, and appears to be controlled by a cyber crime gang known as Russian Spider.
"...gain initial access to corporate networks for Ryuk, and later, Conti ransomware attacks."
"BazaLoader... subsequently installed a ransomware strain called Ryuk."
"The operators of Ryuk ransomware are at it again... There was speculation that the Ryuk actors had moved on to a rebranded version of the ransomware, called Conti."
24 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Prosecutors previously accused Vardanyan and his co-conspirators ... of illegally accessing computer networks to deploy Ryuk ransomware on hundreds of compromised servers and workstations between March 2019 and September 2020.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Prosecutors previously accused Vardanyan and his co-conspirators ... of illegally accessing computer networks to deploy Ryuk ransomware on hundreds of compromised servers and workstations between March 2019 and September 2020.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
title: Suspicious Group And Account Reconnaissance Activity Using Net.EXE ... Detects suspicious reconnaissance command line activity on Windows systems using Net.EXE ... tags: - attack.discovery - attack.t1087.001 - attack.t1087.002
selection_accounts_root: CommandLine|contains: ' accounts ' ... selection_accounts_flags: CommandLine|contains: ' /do' # short for domain ... tags: - attack.discovery - attack.t1087.001 - attack.t1087.002
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
Trickbot is a cybercriminal group that has conducted ransomware campaigns across essential services including healthcare and banking. | The EU designated Vitaly Nikolayevich Kovalev, also known as “Stern,” administrator of the Trickbot ransomware operations who has received more than $300 million in ransom payments.
134 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
171 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family identified as part of the Trickbot Group ecosystem.
Ryuk is a ransomware operation that encrypts victims’ data across servers and workstations and demands Bitcoin payments in exchange for decryption keys. The content describes it as a highly profitable operation that collected substantial ransom payments from U.S. organizations.
Ryuk is a ransomware family used to encrypt victim systems and extort ransom payments from compromised organizations.
Ryuk is ransomware used to encrypt victim systems and extort organizations by demanding Bitcoin payments in exchange for decryption keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.