Ryuk Stealer

Aliases: Sidoh

First seen
2018-08-13 00:00:00
Malware type
credential-stealer, spyware
Family
Malware family
Last IoC activity
2026-06-29 05:56:43
Profile updated
2026-07-07 15:18:55

Targeted industries: healthcare-and-pharmaceutical financial-services government-and-public-sector

Context

Information Stealer that searches for sensitive documents and uploads its results to an FTP server. Skips files with known Ryuk extensions.

Detection coverage

  • 1 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Sidoh_Stealer_Aug_2021_1 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Ryuk Stealer (report)
  • analyst1.com — Nationstate Ransomware With Consecutive Endnotes (report)
  • twitter.com — 1171782155581689858 (report)
  • CrowdStrike — Sidoh Wizard Spiders Mysterious Exfiltration Tool (report)
  • bleepingcomputer.com — Ryuk Related Malware Steals Confidential Military Financial Files (report)

External references