Ryuk ransomware evolved from a targeted enterprise threat with code similarities to HERMES into a faster, more evasive operation that encrypted local disks in under 10 minutes, spread to network shares, deleted shadow copies, disabled recovery options, and in some cases used Wake-on-LAN functionality to reach additional systems. Researchers reported that newer variants obfuscated strings, duplicated themselves under random lan.exe filenames, used combined RSA and AES encryption, and partially encrypted large files to speed attacks; one later change also introduced a flaw in the attackers’ own decryptor that could corrupt large virtual disk and database files even after ransom payment.

Pull IOCs and campaign context straight into your stack.
13 events from the most recent confirmed update back to the earliest known activity.
CISA, the FBI, and HHS issued a joint advisory warning of an increased and imminent Ryuk threat to U.S. hospitals and healthcare providers. The agencies also held a call with healthcare organizations and urged immediate defensive measures, including patching and incident-response preparation.
Universal Health Services was hit by a corporate-wide Ryuk ransomware attack in the month before the late-October 2020 reporting. The incident affected more than 200 medical facilities nationwide and disrupted access to labs, radiology, and patient records.
SentinelOne reported that attackers using TrickBot typically spent about two weeks conducting reconnaissance, credential theft, and lateral movement before deploying Ryuk. The analysis described use of Cobalt Strike, DACheck, Mimikatz, and PsExec to profile networks, gain broad access, and remotely launch ransomware.
Epiq Global detected unauthorized activity on February 29, 2020, when Ryuk began encrypting devices on its network. The company took systems offline globally to contain the attack, disrupting e-discovery services and client access to case documents.
Quick Heal published an article titled "A Deep Dive Into Wakeup On Lan (WoL) Implementation of Ryuk," indicating public reporting on Ryuk's Wake-on-LAN functionality. The provided snippet contains no further technical details.
A December 2019 Ryuk sample analyzed by Vitali Kremez was found to avoid encrypting folders such as bin, boot, dev, etc, lib, sbin, sys, and var. Reporting linked the sample to the City of New Orleans incident and said the change likely aimed to avoid damaging Windows Subsystem for Linux installations on infected Windows systems.
A cybersecurity industry source told BleepingComputer that Epiq Global's eventual Ryuk incident began with a TrickBot infection in December 2019. The intrusion reportedly enabled reconnaissance and credential theft before ransomware deployment.
Check Point reported that over a two-week period in 2018, Ryuk severely impacted at least three organizations, encrypting hundreds of PCs, storage systems, and data center assets. The report said operators had already received more than $640,000 in ransom payments and assessed links to HERMES code or operators.
The Virus Bulletin 2019 presentation states that Ryuk was first seen in August 2018 and was mentioned in a tweet on August 17, 2018. This marks the earliest public emergence of the ransomware family in the provided sources.
The HERMES ransomware was used in the October 2017 attack on Far Eastern International Bank in Taiwan, which involved a SWIFT theft of $60 million that was later recovered. This event is cited as background for later Ryuk/HERMES code-link analysis.
Sophos Rapid Response described containing a Ryuk attack at a life sciences research institute that lost about a week of research data and had to rebuild systems before restoring operations. Investigators traced the compromise to malware installed by a university student using personal-device Citrix access without MFA.
Sky Lakes Medical Center in Oregon and St. Lawrence Health System in New York were struck by Ryuk ransomware in the two days preceding the report. The attacks affected patient treatment and were part of a broader wave targeting U.S. healthcare.
Emsisoft disclosed that a recent Ryuk variant changed footer-length handling in a way that caused the attackers' own decryptor to truncate decrypted files by one byte. The flaw could corrupt some file types, especially VHD/VHDX virtual disks and Oracle database files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 17 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
11 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcenews.sophos.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcembsd.jp
Open sourceblog.emsisoft.com
Open sourceresearch.checkpoint.com
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.