Ryuk

MITRE ATT&CK: S0446 View on attack.mitre.org

Aliases: Ryuk

Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
6 (6 malicious)
Last IoC activity
2026-06-21 10:57:44
Profile updated
2026-07-07 12:37:56

Targeted industries: energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical retail-and-hospitality

Context

Ryuk is a ransomware designed to target enterprise environments that has been used in attacks since at least 2018. Ryuk shares code similarities with Hermes ransomware.

Recent IoC activity

6 malicious indicators in Maltiverse are attributed to Ryuk (S0446). The 6 most recently updated:

Detection coverage

  • 4 YARA rules
  • 556 Sigma rules

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)
  • Native API (attack-pattern)
  • Process Discovery (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Service Stop (attack-pattern)
  • Windows Permissions (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Traffic Signaling (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Process Injection (attack-pattern)
  • Masquerading (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Access Token Manipulation (attack-pattern)
  • Loss of Productivity and Revenue (attack-pattern)

Used by threat actors

Detection rules

  • ARKBIRD_SOLG_MAL_Sidoh_Stealer_Aug_2021_1 (yara-rule)
  • DITEKSHEN_INDICATOR_KB_ID_Ransomware_Ryuk (yara-rule)
  • CAPE_Ryuk (yara-rule)
  • MALPEDIA_Win_Ryuk_Stealer_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • Mandiant — Pick Six Intercepting A Fin6 Intrusion (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • CrowdStrike — Big Game Hunting With Ryuk Another Lucrative Targeted Ransomware (report)
  • Mandiant — A Nasty Trick From Credential Theft Malware To Business Disruption (report)
  • CrowdStrike — Wizard Spider Adds New Feature To Ryuk Ransomware (report)
  • secureworks.com — Gold Ulrick (report)
  • strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
  • analyst1.com — Ransom Mafia Analysis Of The World%E2%80%99S First Ransomware Cartel (report)
  • proofpoint.com — Q4 2020 Threat Report Quarterly Analysis Cybersecurity Trends Tactics And Themes (report)
  • CrowdStrike — Report2021Gtr (report)
  • twitter.com — 1321865315513520128 (report)
  • Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
  • gist.github.com — 6Aa7F61246F53A8Dd4Befea86E832456 (report)
  • youtube.com — Watch (report)
  • Mandiant — The Cycle Of Adversary Pursuit (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • CrowdStrike — Wizard Spider Adversary Update (report)
  • cert.ssi.gouv.fr — Certfr 2019 Act 005 (report)
  • Microsoft — Re54L7V (report)
  • blog.sensecy.com — Global Ransomware Attacks In 2020 The Top 4 Vulnerabilities (report)
  • blogs.blackberry.com — Kraken The Code On Prometheus (report)

External references