Overview
Platforms:
Windows
Variants:
—
Extensions:
.RYK
ATT&CK software:
—
Initial access:
Domain Accounts
Top countries:
—
Observed sectors:
—
Attribution
WIZARD SPIDER
VERIFIED
Core operator attribution
CrowdStrike and MITRE associate the development and deployment of Ryuk ransomware with the WIZARD SPIDER cybercrime ecosystem.
Affiliates
No affiliate information available.
Activity
Recent Observations
Spanish SEPE ransomware attack
March 2021
Major incident
Ryuk ransomware disrupted systems across hundreds of offices belonging to Spain's State Public Employment Service.
Continued enterprise ransomware activity
January 2021
Ransomware activity
Ryuk remained one of the ransomware families observed in major enterprise intrusions during 2021.
U.S. healthcare threat campaign
October 2020
Healthcare targeting
CISA, FBI and HHS warned of increased cybercrime activity targeting U.S. hospitals and healthcare providers with Ryuk and Conti ransomware.
Ryuk deployment resumes
September 2020
Operational activity
WIZARD SPIDER resumed Ryuk deployment after a pause in activity between March and September 2020.
TTPs
ATT&CK coverage:
6 techniques
· 4 tactics
T1078.002
Domain Accounts
VERIFIEDDefense Evasion / Persistence / Privilege Escalation / Initial Access
Ryuk operators used stolen domain administrator accounts to move laterally through victim environments.
T1021.002
SMB/Windows Admin Shares
VERIFIEDLateral Movement
Ryuk used administrative network shares such as C$ for lateral movement and deployment.
T1053.005
Scheduled Task
VERIFIEDExecution / Persistence
Ryuk could remotely create scheduled tasks to execute ransomware on additional systems.
Show more TTPs (3)
T1489
Service Stop
VERIFIEDImpact
Ryuk stopped services and terminated processes to increase the effectiveness of encryption.
T1490
Inhibit System Recovery
VERIFIEDImpact
Ryuk deleted volume shadow copies and modified shadow storage to interfere with system recovery.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Ryuk encrypted victim files using AES and RSA cryptography and generated Ryuk ransom notes.
Victims
Servicio Público de Empleo Estatal (SEPE)
CONFIRMED
Government organization in Spain.
CVEs
No CVE associations available.
Infrastructure
Malware delivery ecosystem
Ryuk deployments were frequently preceded by malware including TrickBot, Emotet and BazarLoader, which provided access and post-exploitation capabilities before ransomware deployment.
Ryuk leak site
Unlike many later ransomware operations, Ryuk was not known to operate a dedicated public data leak site.
Timeline
2021-12
Ryuk activity declines
Ryuk remained present in 2021 intrusion investigations, but Conti had increasingly replaced it as the dominant ransomware associated with the broader WIZARD SPIDER ecosystem.
2021-03
SEPE attack
Ryuk disrupted Spain's State Public Employment Service and affected hundreds of offices.
2020-10
Healthcare campaign warning
U.S. authorities warned of an increased threat from Ryuk and Conti ransomware against hospitals and healthcare providers.
Show more events (3)
2020-09
Ryuk returns
WIZARD SPIDER resumed Ryuk ransomware deployment after several months of reduced activity.
2020-03
Ryuk deployments pause
CrowdStrike observed WIZARD SPIDER cease Ryuk deployment while activity shifted toward Conti.
2018-08
Ryuk first observed
Ryuk ransomware began appearing in targeted big-game hunting attacks against enterprise environments.