Ryuk is a targeted, human-operated ransomware campaign that emerged in 2018 and became prominent between 2019 and 2021. Unlike opportunistic ransomware, Ryuk attacks involved long dwell times, manual reconnaissance, and selective deployment against high-value targets such as healthcare organizations, governments, and large enterprises.
The Ryuk attack lifecycle typically began with phishing emails delivering Emotet, which then installed TrickBot to establish persistence, perform credential harvesting, and enable lateral movement. Attackers escalated privileges to domain administrator, conducted internal reconnaissance, disabled security controls and backups, and manually deployed Ryuk ransomware across critical systems.
Ryuk used strong AES and RSA encryption, deleted shadow copies to prevent recovery, and demanded high ransom payments, often in the millions of dollars. Although Ryuk itself has largely been retired, its tactics directly influenced modern ransomware operations such as Conti and LockBit, making it a foundational example of big-game hunting ransomware.
1. Threat Actor Attribution
Ryuk is attributed to a Russian-speaking cybercriminal group commonly referred to as:
- Wizard Spider
- Also associated with UNC1878 / TEMP.MixMaster
This group also developed or operated:
- Emotet (initial access)
- TrickBot (post-exploitation & lateral movement)
- Conti (Ryuk’s successor)
Ryuk was not sold as Ransomware-as-a-Service (RaaS). It was privately used, meaning attackers carefully chose targets.
2. Strategic Objective of Ryuk Campaigns
The Ryuk campaign focused on “Big Game Hunting”, meaning:
- Target large organizations
- Cause maximum operational disruption
- Demand extremely high ransoms
- Force payment due to downtime pressure
Healthcare and government were especially targeted because downtime could endanger lives or critical services.
3. Full Attack Lifecycle (Kill Chain)
3.1 Initial Access
Phishing Emails
- Malicious Word or Excel attachments
- Macro-enabled documents
- Often themed around invoices, shipping notices, COVID updates
Malware Loaders
- Emotet → installs TrickBot
- TrickBot establishes persistence and reconnaissance
Stolen Credentials
- Reused passwords
- Compromised VPN or RDP accounts
Exposed RDP
-
Weak or brute-forced credentials
3.2 Establishing Persistence
Once TrickBot or similar malware is installed:
- Registry run keys added
- Scheduled tasks created
- Services installed
- Multiple backdoors deployed
This ensures attackers can re-enter even if malware is removed.
3.3 Privilege Escalation
Attackers aim for domain admin access.
Methods include:
- Credential dumping using Mimikatz
- Extracting hashes from LSASS
- Kerberoasting
- Exploiting weak Active Directory configurations
This phase can last days or weeks.
3.4 Internal Reconnaissance
Attackers manually explore the network to identify:
- Domain controllers
- Backup servers
- File servers
- Databases
- Virtualization infrastructure (VMware, Hyper-V)
Commands commonly observed:
net group "Domain Admins" /domainnltest /dclistnet viewwhoamiipconfig /all
3.5 Lateral Movement
Attackers spread laterally using:
- PsExec
- Windows Admin Shares (SMB)
- RDP
- WMI
They deliberately avoid noisy behavior to stay undetected.
3.6 Defense Evasion
Before deploying Ryuk, attackers:
- Disable antivirus and EDR
- Stop backup services
- Delete shadow copies
- Disable Windows recovery
Common commands:
3.7 Ransomware Deployment
Ryuk is deployed manually, often during:
- Weekends
- Holidays
- Night hours
Deployment methods:
- Group Policy Objects (GPO)
- PsExec scripts
- Scheduled tasks
Characteristics of Ryuk encryption:
- Uses AES + RSA
- Encrypts network drives and local files
- Skips some system files to keep OS running
- Targets critical servers first
4. Ransom Note and Extortion
Ryuk leaves a ransom note such as: RyukReadMe.txt
Key traits:
- No automated chat portal
- Victim must email attackers
- Bitcoin payment only
- Ransom often starts at $500,000 to $10+ million
- No public leak threat (pre-double extortion era)
Attackers rely purely on operational downtime pressure.
5. Why Ryuk Was So Effective
Ryuk succeeded because it combined:
- Long dwell time
- Manual decision-making
- Precise targeting
- Destruction of backups
- Attacks on mission-critical systems
Many victims could not restore operations even if backups existed.
6. Evolution and Decline
By late 2020:
- Ryuk operations slowed
- Infrastructure and developers shifted to Conti
- Same tactics, more automation, leak sites added
7. Impact and Real-World Consequences
- Hundreds of hospitals forced offline
- Emergency services disrupted
- Municipal governments shut down for weeks
- Billions in combined losses globally
Ryuk attacks directly contributed to patients being diverted from hospitals.
8. Defensive Lessons Learned
Ryuk reshaped ransomware defense strategies:
Prevention
- Disable macros by default
- MFA on VPN, RDP, admin accounts
- Patch external-facing systems
Detection
- Alert on PsExec usage
- Monitor credential dumping behavior
- Detect backup deletion attempts
Response
- Immutable, offline backups
- Network segmentation
- Tested incident response plans
9. Why Ryuk Still Matters Today
Ryuk established:
- Human-operated ransomware
- Big-game hunting
- Precursor malware ecosystems
- Manual deployment strategy
Modern ransomware groups (LockBit, BlackCat, ALPHV) still follow Ryuk’s model.
Ryuk Campaign → MITRE ATT&CK Mapping (TTP-by-TTP)
Initial Access
-
T1566.001 – Phishing: Attachment
Malicious Word/Excel documents delivering Emotet -
T1190 – Exploit Public-Facing Application
Exploited VPN/RDP vulnerabilities -
T1078 – Valid Accounts
Stolen or brute-forced credentials
Execution
- T1059.003 – Command and Scripting Interpreter: Windows CMD
- T1059.001 – PowerShell
- T1204.002 – User Execution: Malicious File
Persistence
- T1547.001 – Registry Run Keys / Startup Folder
- T1053.005 – Scheduled Task
- T1543.003 – Windows Service
Privilege Escalation
- T1068 – Exploitation for Privilege Escalation
- T1003 – OS Credential Dumping
- LSASS memory dumping
- SAM database access
Defense Evasion
- T1562.001 – Disable or Modify Security Tools
- T1070.004 – File Deletion
- T1490 – Inhibit System Recovery
- Shadow copy deletion
- T1027 – Obfuscated/Encrypted Files
Credential Access
- T1003.001 – LSASS Memory
- T1555 – Credentials from Password Stores
- T1558.003 – Kerberoasting
Discovery
- T1087 – Account Discovery
- T1016 – System Network Configuration Discovery
- T1046 – Network Service Discovery
- T1069 – Permission Group Discovery
Lateral Movement
- T1021.002 – SMB/Windows Admin Shares
- T1021.001 – Remote Desktop Protocol
- T1569.002 – Service Execution (PsExec)
Command and Control
- T1071.001 – Web Protocols
- T1095 – Non-Application Layer Protocol
- T1105 – Ingress Tool Transfer
Impact
- T1486 – Data Encrypted for Impact
- T1490 – Inhibit System Recovery
- T1529 – System Shutdown/Reboot
