Skip to main content
Mallory

Ryuk

Also known asryukryuk_ransomware_group

Ryuk is a prolific ransomware group first identified in 2018 and widely associated with Russia in the provided reporting. It is described as a financially motivated, destructive “big game hunting” ransomware operation that targeted large organizations, including companies, hospitals, local governments, and backup infrastructure. The content links Ryuk to Russia-based cybercrime and notes that numerous major ransomware groups, including Ryuk, have been linked to Russia. The group’s operations commonly involved multi-stage intrusion chains and access provided by other malware and affiliates. The content directly links Ryuk to BazarCall campaigns, BazarLoader/Kegtap, TrickBot, Emotet, Buer Loader, Cobalt Strike, and SystemBC. Reported Ryuk intrusions began with phishing or malspam, then progressed to rapid Active Directory and host discovery using built-in Windows tools and AdFind, credential theft and Kerberoasting with tools such as Rubeus, and lateral movement via WMI, SMB, RDP, remote services, and PowerShell. The group also used BloodHound/SharpHound for AD attack-path mapping. In observed incidents, operators disabled defenses with PowerShell, used GMER to find and shut down hidden processes and antivirus software, stopped backup- and database-related services, modified permissions with icacls, and deleted shadow copies using vssadmin commands such as "vssadmin Delete Shadows /all /quiet" and shadow storage resizing. The content describes Ryuk as using a fast operational tempo in some cases, with progression from phishing to domain-wide ransomware deployment in as little as about five hours or 29 hours in separate incidents. Backup servers were prioritized in multiple reports. Ryuk ransom demands were high-value; one report cited a demand of more than 600 BTC, and the FBI was cited as reporting that $61 million had been paid to the group as of February 2020. Ryuk is also described as part of a broader cybercrime ecosystem. Emotet operators rented access to infected machines to ransomware operations such as Ryuk, and TrickBot infections were described as enabling access for Ryuk deployment. The content states that Silent Ransom Group actors were previously part of the Ryuk and Conti cybercrime syndicate, and that Conti emerged in 2020 as a successor to Ryuk. Reporting also notes financial facilitation tied to Ryuk, including account and exchange services linked to Garantex and laundering support from the Smart/TGR networks; one article states that associates of Ekaterina Zhdanova helped clients including the Ryuk ransomware group obtain overseas tax residency, identification cards, and bank accounts to move illicit funds. Known aliases in the provided content are Ryuk and ryuk_ransomware_group.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics17 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078×2
Valid Accounts
T1566×2
Phishing
TA0002
Execution
1 technique
T1059
Command and Scripting Interpreter
TA0003
Persistence
1 technique
T1078×2
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078×2
Valid Accounts
TA0005
Stealth
1 technique
T1078×2
Valid Accounts
TA0006
Credential Access
1 technique
T1110
Brute Force
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.001
Remote Desktop Protocol
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1090
Proxy
T1090.003
Multi-hop Proxy
T1105
Ingress Tool Transfer
TA0010
Exfiltration
1 technique
T1020
Automated Exfiltration
T1020.001
Traffic Duplication
TA0040
Impact
2 techniques
T1486×8
Data Encrypted for Impact
T1489
Service Stop
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping11

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.