Overview

Platforms: Windows
Variants: —
Extensions: .RYK
ATT&CK software: —
Initial access: Domain Accounts
Top countries: —
Observed sectors: —

Attribution

WIZARD SPIDER VERIFIED
Core operator attribution
CrowdStrike and MITRE associate the development and deployment of Ryuk ransomware with the WIZARD SPIDER cybercrime ecosystem.

Affiliates

No affiliate information available.

Activity

Recent Observations

Spanish SEPE ransomware attack
March 2021
Major incident
Ryuk ransomware disrupted systems across hundreds of offices belonging to Spain's State Public Employment Service.
Continued enterprise ransomware activity
January 2021
Ransomware activity
Ryuk remained one of the ransomware families observed in major enterprise intrusions during 2021.
U.S. healthcare threat campaign
October 2020
Healthcare targeting
CISA, FBI and HHS warned of increased cybercrime activity targeting U.S. hospitals and healthcare providers with Ryuk and Conti ransomware.
Ryuk deployment resumes
September 2020
Operational activity
WIZARD SPIDER resumed Ryuk deployment after a pause in activity between March and September 2020.

TTPs

ATT&CK coverage: 6 techniques · 4 tactics
T1078.002 Domain Accounts
VERIFIED
Defense Evasion / Persistence / Privilege Escalation / Initial Access
Ryuk operators used stolen domain administrator accounts to move laterally through victim environments.
T1021.002 SMB/Windows Admin Shares
VERIFIED
Lateral Movement
Ryuk used administrative network shares such as C$ for lateral movement and deployment.
T1053.005 Scheduled Task
VERIFIED
Execution / Persistence
Ryuk could remotely create scheduled tasks to execute ransomware on additional systems.
Show more TTPs (3)
T1489 Service Stop
VERIFIED
Impact
Ryuk stopped services and terminated processes to increase the effectiveness of encryption.
T1490 Inhibit System Recovery
VERIFIED
Impact
Ryuk deleted volume shadow copies and modified shadow storage to interfere with system recovery.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Ryuk encrypted victim files using AES and RSA cryptography and generated Ryuk ransom notes.

Victims

Servicio Público de Empleo Estatal (SEPE) CONFIRMED
March 2021 Spain Government
Government organization in Spain.

CVEs

No CVE associations available.

Infrastructure

Malware delivery ecosystem
Ryuk deployments were frequently preceded by malware including TrickBot, Emotet and BazarLoader, which provided access and post-exploitation capabilities before ransomware deployment.
Ryuk leak site
Unlike many later ransomware operations, Ryuk was not known to operate a dedicated public data leak site.

Timeline

2021-12
Ryuk activity declines
Ryuk remained present in 2021 intrusion investigations, but Conti had increasingly replaced it as the dominant ransomware associated with the broader WIZARD SPIDER ecosystem.
2021-03
SEPE attack
Ryuk disrupted Spain's State Public Employment Service and affected hundreds of offices.
2020-10
Healthcare campaign warning
U.S. authorities warned of an increased threat from Ryuk and Conti ransomware against hospitals and healthcare providers.
Show more events (3)
2020-09
Ryuk returns
WIZARD SPIDER resumed Ryuk ransomware deployment after several months of reduced activity.
2020-03
Ryuk deployments pause
CrowdStrike observed WIZARD SPIDER cease Ryuk deployment while activity shifted toward Conti.
2018-08
Ryuk first observed
Ryuk ransomware began appearing in targeted big-game hunting attacks against enterprise environments.

Sources

Ryuk — S0446
MITRE ATT&CK
Framework
Wizard Spider — G0102
MITRE ATT&CK
Framework
Wizard Spider
CrowdStrike
Vendor research
Show more sources (5)