Ryuk Ransomware: A Targeted Campaign Break-Down

2018-08-21 • Checkpoint •

https://research.checkpoint.com/ryuk-ransomware-targeted-campaign-break/

Thumbnail for Ryuk Ransomware: A Targeted Campaign Break-Down

Check Point analyzed Ryuk as a targeted ransomware campaign that hit several enterprises worldwide and produced large ransom payments, with infections manually focused on critical systems after prior network mapping and credential collection. The researchers found strong code-level overlap between Ryuk and HERMES ransomware, including similar file-encryption logic, identical encrypted-file marker handling, shared exclusions such as Ahnlab and Microsoft folders, and comparable artifacts including window.bat, PUBLIC, and UNIQUE_ID_DO_NOT_REMOVE. HERMES had previously been used in the Far Eastern International Bank attack commonly attributed to Lazarus, but the report frames Ryuk attribution cautiously as either HERMES operators or another actor possessing HERMES source code. Ryuk’s dropper selected 32- or 64-bit payloads, killed many security, backup, database, and office-related processes and services, established Run-key persistence, and attempted process injection before encrypting files.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9b86a50b36aea5cc4cb60573a3660cf… 2018-08-21 2020-03-09
HASH 1455091954ecf9ccd6fe60cb8e982d9… 2018-08-21 2018-08-21
HASH c51024bb119211c335f95e731cfa9a7… 2018-08-21 2018-08-21
HASH 3012f472969327d5f8c9dac63b8ea9c… 2018-08-21 2018-08-21
HASH b8e463789a076b16a90d1aae73cea9d… 2018-08-21 2018-08-21
HASH 8d3f68b16f0710f858d8c1d2c699260… 2018-08-21 2018-08-21
HASH 113af75f13547be184822f1268f984b… 2018-08-21 2018-08-21
HASH 23f8aa94ffb3c08a62735fe7fee5799… 2018-08-21 2018-08-21

Related Actors

Related Reports

« Back