Netskope Threat Labs

Ryuk

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Ryuk is a targeted ransomware operation that has affected numerous organizations worldwide, including hospitals, municipalities, and large enterprises. Its operators demanded ransoms that rank among the largest on record, deployed the payload only after thorough reconnaissance, and extracted hundreds of millions of dollars in total. The family operated within the Wizard Spider and Conti ecosystems, and although its peak has passed, its tactics shaped the big game hunting model that dominates ransomware today.

First seen
February 2022
Last seen
October 2026

22 techniques across 7 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1057Process Discovery
  • T1083File and Directory Discovery
  • T1614System Location Discovery
  • T1680Local Storage Discovery

TA0008 Lateral Movement

TA0040 Impact

  • T1486Data Encrypted for Impact
  • T1489Service Stop
  • T1490Inhibit System Recovery

TA0112 Defense Impairment

  • T1222File and Directory Permissions Modification
  • T1685Disable or Modify Tools
Alert Name
Dump:Generic.Ransom.Ryuk.00CE8B75
Gen:Variant.Ransom.Ryuk.19
Gen:Variant.Ransom.Ryuk.5
Gen:Variant.Ransom.Ryuk.50
Gen:Variant.Ransom.Ryuk.58
Gen:Variant.Ransom.Ryuk.59
Gen:Variant.Ransom.Ryuk.60
Gen:Variant.Ransom.Ryuk.83
Gen:Variant.Ransom.Ryuk.85
Gen:Variant.Ransom.Ryuk.93