Ryuk Ransomware

Description Summary

Ryuk was a highly damaging targeted ransomware active from 2018 to 2021, operated by the Russian-speaking group Wizard Spider (a.k.a. Grim Spider). It was typically the final-stage payload in intrusions that began with TrickBot, Emotet, or BazarLoader infections, and focused on big-game hunting against enterprises, hospitals, and government. Ryuk's operators and code are the direct lineage of the later Conti operation.

Threat Actor

Wizard Spider / Grim Spider (Russian-speaking). Delivered as the final stage after TrickBot/Emotet/BazarLoader loaders; direct predecessor to Conti.

Technical Indicators

Encryption Extension
.ryk / .RYK (some variants add no extension)
Encryption Algorithm
AES-256 (files) + RSA-4096 (key wrapping)
Ransom Note Name
RyukReadMe.txt / RyukReadMe.html
Targeted Industries
Healthcare, Government, Manufacturing, Financial, Media
First Seen
August 2018
Last Seen
2021 (operators transitioned to Conti)
Geographical Location
United States, Europe, worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 1 T1566 Phishing
Execution x 2 T1204 User Execution (TrickBot/BazarLoader)
T1059.001 PowerShell
Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1055 Process Injection
T1562.001 Disable or Modify Tools
Credential Access x 1 T1003 OS Credential Dumping
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop