Ransomware Group intelligence
Ryuk
InactiveTrack Ryuk with 48 published victims in a single intelligence view.
Overview
Ryuk is tracked by Breach House as a ransomware group with 48 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (9)
Typical Attacks (22)
▼How Ryuk typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Ryuk.
-
What they do: Ryuk can use stolen domain admin accounts to move laterally within a victim domain.
What that means: Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
-
What they do: Ryuk can remotely create a scheduled task to execute itself on a system.
What that means: Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
-
T1059.003 Windows Command Shell Execution
What they do: Ryuk has used cmd.exe to create a Registry entry to establish persistence.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Ryuk has used multiple native APIs including ShellExecuteW to run executables, GetWindowsDirectoryW to create folders, and VirtualAlloc, WriteProcessMemory, and CreateRemoteThread for process injection.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Ryuk has used Wake-on-Lan to power on turned off systems for lateral movement.
What that means: Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control.
-
What they do: Ryuk has used the Windows command line to create a Registry entry under HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
What they do: Ryuk has injected itself into remote processes to encrypt files using a combination of VirtualAlloc, WriteProcessMemory, and CreateRemoteThread.
What that means: Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.
-
What they do: Ryuk has attempted to adjust its token privileges to have the SeDebugPrivilege.
What that means: Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
T1027 Obfuscated Files or Information Stealth
What they do: Ryuk can use anti-disassembly and code transformation obfuscation techniques.
What that means: Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
-
T1036 Masquerading Stealth
What they do: Ryuk can create .dll files that actually contain a Rich Text File format document.
What that means: Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Ryuk has constructed legitimate appearing installation folder paths by calling GetWindowsDirectoryW and then inserting a null byte at the fourth character of the path.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1222.001 Windows Permissions Defense Impairment
What they do: Ryuk can launch icacls <path> /grant Everyone:F /T /C /Q to delete every access-based restrictions on files and directories.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Ryuk has stopped services related to anti-virus.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1016 System Network Configuration Discovery Discovery
What they do: Ryuk has called GetIpNetTable in attempt to identify all mounted drives and hosts that have Address Resolution Protocol (ARP) entries.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1057 Process Discovery Discovery
What they do: Ryuk has called CreateToolhelp32Snapshot to enumerate all running processes.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1083 File and Directory Discovery Discovery
What they do: Ryuk has enumerated files and folders on all mounted drives.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1614.001 System Language Discovery Discovery
What they do: Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1680 Local Storage Discovery Discovery
What they do: Ryuk has called GetLogicalDrives to emumerate all mounted drives, and GetDriveTypeW to determine the drive type.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: Ryuk has used the C$ network share for lateral movement.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Ryuk has called kill.bat for stopping services, disabling services and killing processes.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Ryuk has used vssadmin Delete Shadows /all /quiet to to delete volume shadow copies and vssadmin resize shadowstorage to force deletion of shadow copies created by third-party applications.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (3)
▼Software Ryuk has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Offensive security tooling
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (39)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
3LE4u2csMS9y1MdfgBZ3pDmnDg7VCtX322 |
bitcoin | $770,191 | 2 |
1Kx9TT76PHwk8sw7Ur6PsMWyEtaogX7wWY |
bitcoin | $744,841 | 10 |
15RLWdVnY5n1n7mTvU1zjg67wt86dhYqNj |
bitcoin | $511,549 | 4 |
1L9fYHJJxeLMD2yyhh1cMFU2EWF5ihgAmJ |
bitcoin | $259,505 | 4 |
1FRNVupsCyTjUvF36GxHZrvLaPtY6hgkTm |
bitcoin | $247,268 | 3 |
1Jq3WwsaPA7LXwRNYsfySsd8aojdmkFnW |
bitcoin | $223,222 | 1 |
12vsQry1XrPjPCaH8gWzDJeYT7dhTmpcjL |
bitcoin | $217,381 | 3 |
18eu6KrFgzv8yTMVvKJkRM3YBAyHLonk5G |
bitcoin | $199,279 | 1 |
1C8n86EEttnDjNKM9Tjm7QNVgwGBncQhDs |
bitcoin | $194,905 | 2 |
1FtQnqvjxEK5GJD9PthHM4MtdmkAeTeoRt |
bitcoin | $188,944 | 4 |
1ChnbV4Rt7nsb5acw5YfYyvBFDj1RXcVQu |
bitcoin | $175,710 | 2 |
19AE1YN6Jo8ognKdJQ3xeQQL1mSZyX16op |
bitcoin | $164,740 | 1 |
+27 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
ryuk.txt
Your network has been penetrated. All files on each host in the network have been encrypted with a strong algorithm. Backups were either encrypted or deleted or backup disks were formatted. Shadow copies also removed, so F8 or any other methods may damage encrypted data but not recover. We exclusively have decryption software for your situation No decryption software is available in the public. DO NOT RESET OR SHUTDOWN - files may be damaged. DO NOT RENAME OR MOVE the encrypted and readme files. DO NOT DELETE readme files. This may lead to the impossibility of recovery of the certain files. To get info (decrypt your files) contact us at [email protected] or [email protected] BTC wallet: 14hVKm7Ft2rxDBFTNkkRC3kGstMGp2A4hk Ryuk No system is safe
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (48)
Search, filter and paginate the victim timeline for Ryuk. Showing 1–48 of 48.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Visalia Unified School District id631 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Unnamed biomolecular institute id598 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Villefranche-sur-Saône (Rhône) Hospital Center id582 View details | France | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Baltimore County Public Schools (BCPS) id528 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | K12 (AKA Stride Inc) id524 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | University of Vermont (UVM) Health Network id511 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Sky Lakes Medical Center id509 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | St. Lawrence Health System Hospitals (Canton-Potsdam, Gouverneur, and Massena) id510 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Steelcase Inc. id507 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Sopra Steria id503 View details | France | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Dickinson County Health id499 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Sonoma Valley Hospital id496 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Universal Health Services (UHS) Hospitals id483 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Finastra id345 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Durham id337 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Epiq Global (MSP) id332 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | EMCOR id330 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Havre Public Schools id329 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Port Lavaca City Hall id328 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Electronic Warfare Associates (EWA) id319 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Tampa Bay Times id318 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Volusia County Library System id315 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | US Coast Guard id310 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Tribune Publishing id311 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Onkaparinga Council id301 View details | Australia | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Prosegur id299 View details | Spain | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | Louisiana’s Office of Technology Services (OTS) id297 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | Las Cruces Public School District id293 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | National Veterinary Associates id292 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Pitney Bowes id290 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Cherry Hill School District id286 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | (3) DCH Health System hospitals (Tuscaloosa, Fayetter, and Northport, AL) id285 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | Ayuntamiento de Jerez (Jerez City Council) id284 View details | Spain | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Rockville Centre School District id282 View details | United States | Education | — | |
|
No additional victim description available. |
|||||
| Ransomware | Town of Collierville id281 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | La Porte County, Indiana id280 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of New Bedford, Massachusetts id279 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Village of Key Biscayne, Florida id278 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Lake City, Florida id277 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | CloudJumper id274 View details | United States | IT | — | |
|
No additional victim description available. |
|||||
| Ransomware | Metro Presort id272 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Cartersville id271 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Imperial County id268 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Stuart City id269 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Mitsubishi Canada Aerospace id263 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Jackson County, Georgia id260 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Committee for Public Counsel id259 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||
| Ransomware | Onslow County Water and Sewer id254 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||