logo

The Ryuk Ransomware

ID: 07864d70-e578-4f29-a8a3-56da3b299e86

STIX ID: report--07864d70-e578-4f29-a8a3-56da3b299e86

Threat Score

85/100

Uploaded: 2026-07-30

Published Date: 2026-07-30

Last Modified Date: 2026-08-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:A1
...
...
This ANSSI report analyzes the Ryuk ransomware: its origins from Hermes, operational behaviour (file encryption, process/service termination, shadow copy deletion, Wake-on-LAN), common infection chains via Emotet/TrickBot/BazarLoader/BazarBackdoor/Buer, and associated cybercriminal groups (Wizard Spider, UNC1878, FIN6). It documents victimology (high-value 'big game' targets including US healthcare), provides a technical appendix on a 2021 self-propagating Ryuk variant (replication via SMB, scheduled tasks, sample hashes and mutex/propagation behavior), and offers mitigation/containment considerations.