Ryuk Stealer
Aliases: Sidoh
- First seen
- 2018-08-13 00:00:00
- Malware type
- credential-stealer, spyware
- Family
- Malware family
- Last IoC activity
- 2026-06-29 05:56:43
- Profile updated
- 2026-07-07 15:18:55
Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector
Context
Information Stealer that searches for sensitive documents and uploads its results to an FTP server. Skips files with known Ryuk extensions.
Detection coverage
- 1 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Sidoh_Stealer_Aug_2021_1 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Ryuk Stealer (report)
- analyst1.com — Nationstate Ransomware With Consecutive Endnotes (report)
- twitter.com — 1171782155581689858 (report)
- CrowdStrike — Sidoh Wizard Spiders Mysterious Exfiltration Tool (report)
- bleepingcomputer.com — Ryuk Related Malware Steals Confidential Military Financial Files (report)