The Ryuk Ransomware
ID: 07864d70-e578-4f29-a8a3-56da3b299e86
STIX ID: report--07864d70-e578-4f29-a8a3-56da3b299e86
Threat Score
85/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
This ANSSI report analyzes the Ryuk ransomware: its origins from Hermes, operational behaviour (file encryption, process/service termination, shadow copy deletion, Wake-on-LAN), common infection chains via Emotet/TrickBot/BazarLoader/BazarBackdoor/Buer, and associated cybercriminal groups (Wizard Spider, UNC1878, FIN6). It documents victimology (high-value 'big game' targets including US healthcare), provides a technical appendix on a 2021 self-propagating Ryuk variant (replication via SMB, scheduled tasks, sample hashes and mutex/propagation behavior), and offers mitigation/containment considerations.
