Researchers documented a malware family dubbed Ryuk Stealer that searches infected systems and mapped network shares for high-value documents, then uploads matching files to attacker-controlled FTP servers. The malware focuses on sensitive .docx, .xlsx, and other selected file types, filtering them by filename and, in newer variants, by file contents using keywords tied to military, government, law enforcement, banking, finance, personal, and confidential material; some samples also look for U.S. Social Security number-like patterns.
Technical analysis found multiple links to the Ryuk ransomware ecosystem, including overlapping exclusion logic, an unused function that appends the .RYK extension, and development metadata, although researchers said attribution to the Ryuk operators remains unconfirmed. Later samples adopted a more complex three-stage packed design, used Windows callback and hidden-window techniques such as RegisterClassEx and CreateWindowEx to unpack and run payloads, could delete a supplied file path for cleanup, and were capable of probing nearby hosts through ARP-derived network information and administrative shares, indicating a tool built to steal valuable data before or alongside ransomware activity.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
A newer Ryuk Stealer sample carried a PE header compile timestamp of 2020-01-19 00:11:32. This sample later became the basis for technical analysis of an expanded and more heavily packed variant.
A newer Ryuk Stealer sample was identified in late January 2020. This variant expanded targeting beyond Office files and introduced more advanced packing and execution techniques.
Researchers found the 2019 Ryuk Stealer variant scanned local drives and network shares for valid .docx and .xlsx files whose filenames matched sensitive keywords tied to finance, government, military, law enforcement, and personal data. Matching files were uploaded to an attacker-controlled FTP server, and the sample showed code-level ties to Ryuk ransomware without proving common operators.
The first known Ryuk Stealer sample was discovered in September 2019. It was identified as a file-stealing malware family focused on collecting sensitive documents rather than encrypting them.
Researchers discovered a new Ryuk Stealer variant that added file-content scanning, targeted more file types including .pdf, .doc, .xls, .cpp, .h, wallet.dat, and .jpg, and searched for a broader set of military, government, banking, law-enforcement, and personal-data keywords before exfiltration. The malware uploaded matching files to attacker-controlled FTP infrastructure, though the embedded FTP sites were down when reported.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
mbsd.jp
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.