Ryuk Ransomware Explanation and MITRE ATT&CK Mapping

Ryuk is a targeted, human-operated ransomware campaign that emerged in 2018 and became prominent between 2019 and 2021. Unlike opportunistic ransomware, Ryuk attacks involved long dwell times, manual reconnaissance, and selective deployment against high-value targets such as healthcare organizations, governments, and large enterprises.

The Ryuk attack lifecycle typically began with phishing emails delivering Emotet, which then installed TrickBot to establish persistence, perform credential harvesting, and enable lateral movement. Attackers escalated privileges to domain administrator, conducted internal reconnaissance, disabled security controls and backups, and manually deployed Ryuk ransomware across critical systems.

Ryuk used strong AES and RSA encryption, deleted shadow copies to prevent recovery, and demanded high ransom payments, often in the millions of dollars. Although Ryuk itself has largely been retired, its tactics directly influenced modern ransomware operations such as Conti and LockBit, making it a foundational example of big-game hunting ransomware.

1. Threat Actor Attribution

Ryuk is attributed to a Russian-speaking cybercriminal group commonly referred to as:

  • Wizard Spider
  • Also associated with UNC1878 / TEMP.MixMaster

This group also developed or operated:

  • Emotet (initial access)
  • TrickBot (post-exploitation & lateral movement)
  • Conti (Ryuk’s successor)

Ryuk was not sold as Ransomware-as-a-Service (RaaS). It was privately used, meaning attackers carefully chose targets.


2. Strategic Objective of Ryuk Campaigns

The Ryuk campaign focused on “Big Game Hunting”, meaning:

  • Target large organizations
  • Cause maximum operational disruption
  • Demand extremely high ransoms
  • Force payment due to downtime pressure

Healthcare and government were especially targeted because downtime could endanger lives or critical services.


3. Full Attack Lifecycle (Kill Chain)

3.1 Initial Access

Phishing Emails

  • Malicious Word or Excel attachments
  • Macro-enabled documents
  • Often themed around invoices, shipping notices, COVID updates

Malware Loaders

  • Emotet → installs TrickBot
  • TrickBot establishes persistence and reconnaissance

Stolen Credentials

  • Reused passwords
  • Compromised VPN or RDP accounts

Exposed RDP

  • Weak or brute-forced credentials


3.2 Establishing Persistence

Once TrickBot or similar malware is installed:

  • Registry run keys added
  • Scheduled tasks created
  • Services installed
  • Multiple backdoors deployed

This ensures attackers can re-enter even if malware is removed.


3.3 Privilege Escalation

Attackers aim for domain admin access.

Methods include:

  • Credential dumping using Mimikatz
  • Extracting hashes from LSASS
  • Kerberoasting
  • Exploiting weak Active Directory configurations

This phase can last days or weeks.


3.4 Internal Reconnaissance

Attackers manually explore the network to identify:

  • Domain controllers
  • Backup servers
  • File servers
  • Databases
  • Virtualization infrastructure (VMware, Hyper-V)

Commands commonly observed:

  • net group "Domain Admins" /domain
  • nltest /dclist
  • net view
  • whoami
  • ipconfig /all

3.5 Lateral Movement

Attackers spread laterally using:

  • PsExec
  • Windows Admin Shares (SMB)
  • RDP
  • WMI

They deliberately avoid noisy behavior to stay undetected.


3.6 Defense Evasion

Before deploying Ryuk, attackers:

  • Disable antivirus and EDR
  • Stop backup services
  • Delete shadow copies
  • Disable Windows recovery

Common commands:

  • vssadmin delete shadows /all /quiet
  • bcdedit /set {default} recoveryenabled no
  • wbadmin delete catalog -quiet

3.7 Ransomware Deployment

Ryuk is deployed manually, often during:

  • Weekends
  • Holidays
  • Night hours

Deployment methods:

  • Group Policy Objects (GPO)
  • PsExec scripts
  • Scheduled tasks

Characteristics of Ryuk encryption:

  • Uses AES + RSA
  • Encrypts network drives and local files
  • Skips some system files to keep OS running
  • Targets critical servers first

4. Ransom Note and Extortion

Ryuk leaves a ransom note such as: RyukReadMe.txt

Key traits:

  • No automated chat portal
  • Victim must email attackers
  • Bitcoin payment only
  • Ransom often starts at $500,000 to $10+ million
  • No public leak threat (pre-double extortion era)

Attackers rely purely on operational downtime pressure.


5. Why Ryuk Was So Effective

Ryuk succeeded because it combined:

  • Long dwell time
  • Manual decision-making
  • Precise targeting
  • Destruction of backups
  • Attacks on mission-critical systems

Many victims could not restore operations even if backups existed.


6. Evolution and Decline

By late 2020:

  • Ryuk operations slowed
  • Infrastructure and developers shifted to Conti
  • Same tactics, more automation, leak sites added

7. Impact and Real-World Consequences

  • Hundreds of hospitals forced offline
  • Emergency services disrupted
  • Municipal governments shut down for weeks
  • Billions in combined losses globally

Ryuk attacks directly contributed to patients being diverted from hospitals.


8. Defensive Lessons Learned

Ryuk reshaped ransomware defense strategies:

Prevention

  • Disable macros by default
  • MFA on VPN, RDP, admin accounts
  • Patch external-facing systems

Detection

  • Alert on PsExec usage
  • Monitor credential dumping behavior
  • Detect backup deletion attempts

Response

  • Immutable, offline backups
  • Network segmentation
  • Tested incident response plans

9. Why Ryuk Still Matters Today

Ryuk established:

  • Human-operated ransomware
  • Big-game hunting
  • Precursor malware ecosystems
  • Manual deployment strategy

Modern ransomware groups (LockBit, BlackCat, ALPHV) still follow Ryuk’s model.

Ryuk Campaign → MITRE ATT&CK Mapping (TTP-by-TTP)

Initial Access

  • T1566.001 – Phishing: Attachment
    Malicious Word/Excel documents delivering Emotet

  • T1190 – Exploit Public-Facing Application
    Exploited VPN/RDP vulnerabilities

  • T1078 – Valid Accounts
    Stolen or brute-forced credentials


Execution

  • T1059.003 – Command and Scripting Interpreter: Windows CMD
  • T1059.001 – PowerShell
  • T1204.002 – User Execution: Malicious File

Persistence

  • T1547.001 – Registry Run Keys / Startup Folder
  • T1053.005 – Scheduled Task
  • T1543.003 – Windows Service

Privilege Escalation

  • T1068 – Exploitation for Privilege Escalation
  • T1003 – OS Credential Dumping
    • LSASS memory dumping
    • SAM database access

Defense Evasion

  • T1562.001 – Disable or Modify Security Tools
  • T1070.004 – File Deletion
  • T1490 – Inhibit System Recovery
    • Shadow copy deletion
  • T1027 – Obfuscated/Encrypted Files

Credential Access

  • T1003.001 – LSASS Memory
  • T1555 – Credentials from Password Stores
  • T1558.003 – Kerberoasting

Discovery

  • T1087 – Account Discovery
  • T1016 – System Network Configuration Discovery
  • T1046 – Network Service Discovery
  • T1069 – Permission Group Discovery

Lateral Movement

  • T1021.002 – SMB/Windows Admin Shares
  • T1021.001 – Remote Desktop Protocol
  • T1569.002 – Service Execution (PsExec)

Command and Control

  • T1071.001 – Web Protocols
  • T1095 – Non-Application Layer Protocol
  • T1105 – Ingress Tool Transfer

Impact

  • T1486 – Data Encrypted for Impact
  • T1490 – Inhibit System Recovery
  • T1529 – System Shutdown/Reboot