Ryuk Stealer is a Windows data-theft malware associated with the Ryuk ransomware ecosystem. First observed in 2019, it is designed to identify, collect, and exfiltrate high-value files from infected systems and mounted network locations, with targeting logic focused on sensitive business, government, military, financial, banking, law-enforcement, and personal data. The malware has been described as a custom exfiltration utility aligned with ransomware operations, supporting the broader double-extortion model in which data theft accompanies or precedes encryption.
Ryuk Stealer selectively steals files rather than collecting data indiscriminately. It enumerates local drives and mapped network drives, filters candidate files by extension, filename keywords, file-content keywords, and patterns resembling U.S. Social Security numbers, and uploads matching files to attacker-controlled FTP infrastructure. Reported targeting includes office documents, PDFs, source-code-related files, images, and wallet data, with keyword sets oriented toward confidential, military, intelligence, government, financial, and investigative material. It also renames uploaded files to avoid collisions on the remote server.
The malware includes network-aware behavior beyond the local host. It can use ARP-derived network information to identify other reachable systems and attempt access to administrative shares in order to collect additional files. It also contains exclusion logic for certain files and folders, with portions of that logic overlapping Ryuk ransomware exclusions, reinforcing the assessment of a developmental or operational relationship between the two.
Later Ryuk Stealer samples adopted a more complex staged and packed architecture intended to hinder analysis and detection. Reported techniques include multi-stage encrypted payload storage, in-memory unpacking, executable memory allocation, and abuse of Windows GUI callback mechanisms through hidden-window message handling to trigger decryption and execution. The malware can also delete a file path supplied on the command line, likely as a cleanup or self-concealment measure.
Ryuk Stealer is best understood as a custom exfiltration tool built to support financially motivated intrusion activity linked to Ryuk-related operators. Although definitive public proof tying its deployment to confirmed Ryuk ransomware incidents has been reported as lacking, the malware’s development metadata, exclusion overlap, and operational design strongly indicate a close connection to Ryuk-associated attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of a custom data exfiltration tool used in ransomware operations; no further detail is provided in this content.
A named data theft tool cited as another example of custom exfiltration tooling associated with ransomware operations.
Referenced as an earlier example of a custom data exfiltration tool developed by ransomware operators.
File-stealing malware that collects and exfiltrates selected high-value files from infected systems and mapped/network-accessible locations to attacker-controlled FTP servers. The sample described uses multi-stage encrypted unpacking, abuses Windows callback functions for anti-analysis, can delete a file path passed as its first argument for cleanup/evidence removal, filters files by extension/name/content, and also targets files on other hosts via network shares.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.