Ryuk is a targeted Windows ransomware family first observed in 2018 and widely associated with high-impact intrusions against enterprises, government entities, healthcare organizations, municipalities, and educational institutions. It is commonly linked to post-compromise deployment chains involving Emotet and TrickBot, and has also been distributed through other criminal malware delivery ecosystems such as ZLoader. Ryuk is generally operated after attackers have already obtained footholds and administrative access in victim environments, making it characteristic of hands-on, enterprise-scale ransomware operations rather than opportunistic commodity encryption.
Technically, Ryuk is derived from the Hermes ransomware codebase but evolved into a distinct family customized per victim. It encrypts files across local and accessible remote systems, drops ransom notes, and can render systems unusable if boot-critical files are encrypted. Variants have demonstrated network-aware behavior, including discovery of neighboring hosts via ARP information and probing of reachable systems before attempting encryption over Windows administrative shares. Later variants added Wake-on-LAN functionality to power on sleeping hosts and then encrypt them across the network, increasing impact within flat internal environments.
Ryuk has been observed stopping services and terminating processes, particularly security, backup, and productivity applications, to maximize file access and hinder recovery. It has also used process injection and native Windows APIs for execution and evasion. Older variants established persistence through Registry Run entries and have been documented creating scheduled tasks remotely for execution on other systems. The malware can execute without elevated privileges, but its full network-encryption behavior depends on administrative access to remote shares; it does not itself include confirmed credential-theft, brute-force, or privilege-escalation logic for obtaining that access.
Operationally, Ryuk has been tied to financially motivated cybercrime clusters often associated with Wizard Spider and related ecosystems. It has been described as a predecessor to Conti, with some tradecraft overlap in network-based encryption behavior. Ryuk-related activity has also been discussed alongside double-extortion-era developments, including possible use of companion tooling for data theft, though direct use of such tooling in every Ryuk intrusion is not confirmed. Ryuk became notable for large ransom demands and severe disruption to critical services, especially in healthcare and public-sector environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To quickly gain Windows domain admin credentials, Carmakal told BleepingComputer that the group had been seen using the Windows ZeroLogon vulnerability. For this reason, users must install necessary patches on all Windows servers. | the U.S. government warned healthcare providers that Ryuk ransomware is actively targeting the healthcare industry
18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ryuk Ransomware: Ryuk is a highly sophisticated type of ransomware that is being used to target organizations all over the world since its discovery in August 2018.
...this included Trickbot, Emotet, BazarLoader, IcedID, CobaltStrike, and the Ryuk, Conti, and Quantum ransomware strains.
Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware.
Conti popularized the modern ransomware model with its original project, Ryuk, which was delivered via Emotet dropping Trickbot.
À l’été 2020... un incident ayant abouti six semaines après la compromission initiale au chiffrement de la victime par le rançongiciel Ryuk.
The TrickBot Gang... commonly leading to Conti and Ryuk ransomware attacks... other ransomware operations linked to TrickBot, such as Conti and Ryuk...
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
crypters, which are also referred to as loaders or packers, are applications designed to encrypt and obfuscate malware to evade detection by antivirus (AV) scanners and hinder analysis.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
インジェクションの手口は、マルウェアにおいては非常にスタンダードなWriteProcessMemoryによるもので、自分自身をインジェクションし、相手のプロセス内からも不正活動を開始させます。
具体的には、現在のネットワークアダプタに関連付けられた端末のIPアドレスを取得し、[10.][172.16.][192.168.]で始まるかどうか(つまりプライペートIPの範囲かどうか)を調べます。
Ryukの該当機能は、「NT AUTHORITY」(つまりシステム関連)に属するプロセスのリストを作成し、それらのうち「csrss.exe」「explorer.exe」「lsass.exe」以外の全プロセスを対象にインジェクションを行います。
Ryukは上記のように眠っていた端末を起こした後、ping送信による疎通確認を利用してネットワーク上に現存する端末を探索していきます。
It was able to gain access via Remote Desktop Services or other direct methods
pingの応答があった端末が見つかった場合、該当端末の管理共有(C$等)にアクセスを試みます。管理共有にアクセスできた場合、配下の全てのファイルを暗号化していきます。
The widespread primary motive of both these campaigns appear to be to the exfiltration of sensitive information... Exfiltrate design, supply chain information, sensitive information, Personally Identifiable Information (PII), Customer Identifiable Information (CII)
To reduce the likelihood of being detected by an antimalware product, TrickBot also tries to disable and delete Windows Defender.
This campaign used many advanced persistence, lateral movement, and detection evasion measures, including attempts to disable Windows Defender, the use of EternalBlue to spread, and the stopping of multiple services and processes related to anti malware products.
306 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ryuk is ransomware associated in the article with TrickBot-enabled intrusions and discussed as a possible predecessor or related lineage to Conti.
Related Articles: Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Ryuk is ransomware that encrypts files using RSA and AES, appends the .ryk extension, creates a new thread for each file, deletes shadow copies, disables recovery options, adjusts permissions to access drives, duplicates itself, and uses self-injection and string obfuscation to evade detection while accelerating encryption speed.
A ransomware family identified as part of the Trickbot Group ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.