Ryuk

S0446

Malware.View on attack.mitre.org

About this malware

Ryuk is a ransomware designed to target enterprise environments that has been used in attacks since at least 2018. Ryuk shares code similarities with Hermes ransomware.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1016
System Network Configuration Discovery

Ryuk has called GetIpNetTable in attempt to identify all mounted drives and hosts that have Address Resolution Protocol (ARP) entries.

T1021.002
SMB/Windows Admin Shares

Ryuk has used the C$ network share for lateral movement.

T1027
Obfuscated Files or Information

Ryuk can use anti-disassembly and code transformation obfuscation techniques.

T1036
Masquerading

Ryuk can create .dll files that actually contain a Rich Text File format document.

T1036.005
Match Legitimate Resource Name or Location

Ryuk has constructed legitimate appearing installation folder paths by calling GetWindowsDirectoryW and then inserting a null byte at the fourth character of the path. For Windows Vista or higher, the path would appear as C:\Users\Public.

T1053.005
Scheduled Task

Ryuk can remotely create a scheduled task to execute itself on a system.

T1055
Process Injection

Ryuk has injected itself into remote processes to encrypt files using a combination of VirtualAlloc, WriteProcessMemory, and CreateRemoteThread.

T1057
Process Discovery

Ryuk has called CreateToolhelp32Snapshot to enumerate all running processes.

T1059.003
Windows Command Shell

Ryuk has used cmd.exe to create a Registry entry to establish persistence.

T1078.002
Domain Accounts

Ryuk can use stolen domain admin accounts to move laterally within a victim domain.

T1083
File and Directory Discovery

Ryuk has enumerated files and folders on all mounted drives.

T1106
Native API

Ryuk has used multiple native APIs including ShellExecuteW to run executables,GetWindowsDirectoryW to create folders, and VirtualAlloc, WriteProcessMemory, and CreateRemoteThread for process injection.

T1134
Access Token Manipulation

Ryuk has attempted to adjust its token privileges to have the SeDebugPrivilege.

T1205
Traffic Signaling

Ryuk has used Wake-on-Lan to power on turned off systems for lateral movement.

T1222.001
Windows Permissions

Ryuk can launch icacls <path> /grant Everyone:F /T /C /Q to delete every access-based restrictions on files and directories.

View all 22 procedure examples

Groups that use it2

Campaigns0

None recorded.

References3

  1. CrowdStrike Ryuk January 2019 Open source
    Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.
  2. FireEye FIN6 Apr 2019 Open source
    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.
  3. FireEye Ryuk and Trickbot January 2019 Open source
    Goody, K., et al (2019, January 11). A Nasty Trick: From Credential Theft Malware to Business Disruption. Retrieved May 12, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.