Description Summary
Ryuk was a highly damaging targeted ransomware active from 2018 to 2021, operated by the Russian-speaking group Wizard Spider (a.k.a. Grim Spider). It was typically the final-stage payload in intrusions that began with TrickBot, Emotet, or BazarLoader infections, and focused on big-game hunting against enterprises, hospitals, and government. Ryuk's operators and code are the direct lineage of the later Conti operation.
Threat Actor
Wizard Spider / Grim Spider (Russian-speaking). Delivered as the final stage after TrickBot/Emotet/BazarLoader loaders; direct predecessor to Conti.
Technical Indicators
Encryption Extension
.ryk / .RYK (some variants add no extension)
Encryption Algorithm
AES-256 (files) + RSA-4096 (key wrapping)
Ransom Note Name
RyukReadMe.txt / RyukReadMe.html
Targeted Industries
Healthcare, Government, Manufacturing, Financial, Media
First Seen
August 2018
Last Seen
2021 (operators transitioned to Conti)
Geographical Location
United States, Europe, worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 1 | T1566 | Phishing |
| Execution x 2 | T1204 | User Execution (TrickBot/BazarLoader) |
| T1059.001 | PowerShell | |
| Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1055 | Process Injection |
| T1562.001 | Disable or Modify Tools | |
| Credential Access x 1 | T1003 | OS Credential Dumping |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |