Ryuk Ransomware Attack

Published: 8/27/2026

Written By: Lizzie Danielson

Key takeaways

  • Ryuk ransomware is a human-operated threat that typically targets large organizations that can’t afford downtime, such as hospitals, schools, and local governments. Once deployed, it can encrypt systems across the network, prompting the operators to demand payment, usually in Bitcoin.
  • In many cases, Ryuk operators spend days or weeks quietly moving through the network. In others, they compress the entire attack chain into just a few hours.
  • Because Ryuk operators rely heavily on stolen credentials, Remote Desktop Protocol (RDP), and admin tools, traditional antivirus frequently doesn’t trigger until late in the attack.

Ryuk is a high-stakes malicious software (malware) used to target large organizations for massive ransoms. Operators of ransomware tend to target healthcare organizations, schools, and private businesses. These organizations can’t afford downtime and are often willing to pay millions of dollars in recovery costs and Bitcoin ransoms. But even when companies choose not to pay the ransom, the costs remain high.

While there isn’t a foolproof way to avoid ransomware, this guide provides a practical Ryuk ransomware analysis to improve your cybersecurity posture. You’ll learn how to spot the threat early and stop the attack before ransomware disrupts your systems.

What’s Ryuk ransomware?

Ryuk is an infamous type of ransomware known for big game hunting. Since its initial discovery in 2018, experts have investigated several sources of the malware and now believe Russian language group Wizard Spider created it. Instead of using a quick, automated attack, these threat actors often spend days or weeks inside a compromised network. During this time, they perform recon, steal credentials, and identify the most critical files to guarantee a high ransom payout.

How Ryuk attacks differ from commodity ransomware

Off-the-shelf (commodity) ransomware casts a wide net and spreads via automated methods like phishing or malicious downloads. Threat actors use it to capture as many unsuspecting victims as possible to get many smaller ransom payouts. Ryuk, on the other hand, is a bespoke human-operated threat used exclusively for big game hunting to secure the largest ransom possible. The threat actors often use Trickbot or Emotet malware to gain access, and then manually compromise networks to identify critical assets.

Ryuk ransomware attacks examples

Ryuk enables a lucrative attack for the hackers behind it, and it leads to big losses in downtime and ransoms for the organizations affected. Examples include:

  • Tribune Publishing (2018): In one of the earliest high-profile ransomware attacks, Ryuk disrupted the printing of major newspapers like the Los Angeles Times. Tribune didn’t pay a ransom, but papers were delayed by up to a full day.
  • Jackson County, Georgia (2019): This attack knocked out most of the county’s IT systems, aside from emergency services. The municipality paid $400,000 in Bitcoin ransom via a consultant to get a decryption key and restore their systems.
  • Universal Health Services (2020): This attack impacted over 400 hospitals, forcing healthcare professionals to use pen and paper for patient details. UHS did not pay the ransom, but public filings and incident analyses report tens of millions of dollars in lost revenue and recovery costs.
  • Spanish Government (2021): Ryuk infected roughly 710 offices for the Servicio Público de Empleo Estatal (SEPE), the agency responsible for paying out unemployment benefits. This disrupted appointments and payouts for Spanish residents, though the operators.

The Ryuk ransomware attack explained

Threat actors leveraging Ryuk usually deploy ransomware expertly and take their time after entering a system. They know that remaining embedded longer increases the damage they can inflict on their intended victims. However, spending long periods as an unauthorized guest in a system carries extra risks, as it raises the probability of being spotted. Organizations can use this window to block the threat before final deployment.

Initial access and reconnaissance

Ryuk threat actors often gain initial access via social engineering tactics like spear-phishing emails containing malicious attachments that drop malware like Emotet or Trickbot to establish a foothold. The attackers can then use tools like AdFind to query the Active Directory to locate valuable systems to target.

Lateral movement and privilege escalation

After the initial infection, threat actors often use tools like Cobalt Strike or Remote Desktop Protocol (RDP) to move laterally through the system. They can also use malware like Mimikatz to steal credentials and escalate privileges with the goal of compromising a target. At this point, threat actors can then spread an executable file (.exe) or payload to every endpoint in the organization.

Preparing for deployment

Before the final attack, threat actors must disable defenses. They achieve this by killing security processes—such as EDR and antivirus agents—and disabling logging wherever possible. They also delete previous versions (shadow copies) using the vssadmin command-line utility and stop backup services. Finally, they encrypt production files—and, where possible, delete or encrypt accessible backups—so that restoring without paying becomes slow, costly, or impossible.

Ryuk deployment and encryption

In the final stage, threat actors use the command-line tool PsExec or the Group Policy Object (GPO) directory to push the Ryuk payload across the domain. The malicious attack uses Advanced Encryption Standard (AES) and RSA encryption to lock files, requiring a secure key exchange. In many campaigns, encrypted files receive a new extension (commonly `.ryk`), and a text ransom note is dropped in each directory.

Behavioral signals Huntress SOC sees before Ryuk deploys

Our SOC analysts have encountered Ryuk on numerous occasions and now spot these signals before deployment. Security teams can use these indicators to speed up cybersecurity detection and block the attack before it escalates by identifying:

  • Internal network scanning: Threat actors often send network diagnostic packets called Internet Control Message Protocol (ICMP) pings to map the network and identify new systems to target for infection. They may also use Server Message Block (SMB) enumeration for this purpose.
  • Unusual network traffic: Your team may notice large file transfers or RDP connections from external IP addresses at odd hours.
  • Modifying file permissions: Threat actors use the Integrity Control Access Control Lists (icacls) command-line utility to grant broad permissions,ensuring the ransomware process can access and encrypt files without hitting errors.
  • Unusual binary execution: The presence of seemingly random (pseudorandomly) named .exe files in public directories, such as C:\\Users\\Public often signals a malware infection like Ryuk.
  • Administrative share access: Threat actors use hidden administrative network shares like ADMIN$ or C$ to manually move the Ryuk payload from a central server to every endpoint on the network.

Why traditional antivirus misses Ryuk until it's too late

Traditional antivirus focuses on known malicious binaries. Ryuk operators, however, lean heavily on stolen credentials, RDP, and admin tools (PsExec, PowerShell, `icacls`, `vssadmin`). That means a lot of their activity looks like legitimate admin work until very late in the attack—often when encryption has already started.

Consequently, the best window for stopping this malicious attack is as early as possible. Ideally, your team should act while threat actors are still completing initial access and recon.

How Huntress Managed EDR stops Ryuk before encryption

In the hours before the UHS Ryuk ransomware deployment, employees saw threat actors disabling antivirus software and accessing hard drives. Yet, the cybersecurity team did not act quickly enough to stop deployment.

Huntress Managed EDR is designed to detect and respond to Ryuk-style behaviors early—reconnaissance, lateral movement, backup tampering—so your team has a chance to contain the intrusion before widespread encryption.

Our human-led SOC, supported by automation and AI-driven detections, provides 24/7 monitoring and fast response, with mean time to respond (MTTR) measured in minutes for most escalated incidents.

By catching human-operated ransomware in its early stages, Huntress can help reduce the likelihood and potential impact of Ryuk-class incidents that have cost large organizations tens of millions of dollars.

Schedule your free demo today.

Related Educational Articles and Videos

Read more about Ransomware Explained: A Hub for Guides, Resources, & Solutions
Ransomware Explained: A Hub for Guides, Resources, & Solutions
Explore our Ransomware Guide to learn about the threat it poses to your business, the effects of an attack, and what you can do to protect your endpoints.
Read more about How Ransomware Attacks Happen
How Ransomware Attacks Happen
Ransomware
Video

Ransomware is a type of malware that cuts off your access to computers, systems, or networks. Watch the video from our Security Operations Center (SOC) for a breakdown of the ransomware attack path, so you can spot it early, shut it down, and steer clear of hacker paydays.

Read more about Before Ransomware Strikes: Attack Playbook
Before Ransomware Strikes: Attack Playbook
Ransomware

By the time you see the ransom note, the attack's been underway for hours, sometimes days. The encryption is the last step, not the first. If you only react when files lock up, you've already lost the part that mattered.


Ryuk Ransomware FAQs

Many documented Ryuk intrusions have taken several days between initial compromise and mass encryption, with some campaigns operating for weeks. More recently, responders have seen Ryuk operators complete an entire attack—from initial access to full domain encryption—in as little as three hours.

Ryuk threat actors often manually disable cybersecurity controls early on in the attack. Consequently, no matter how effective the antivirus tool is, it can’t successfully spot unauthorized access while it’s off. However, some cybersecurity tools may spot the early attempts in time, such as flagging the initial malspam email.

Early indicators include:

  • An infected endpoint running Emotet or Trickbot
  • AdFind network scanning
  • Deletion of shadow copies via vssadmin
  • Renamed files with a .ryk extension

Stop Ransomware Before It Stops Your Business.

Cybercriminals never rest, but you can. Request a free demo to see how Huntress delivers the 24/7 monitoring and protection your institution needs to stay resilient against evolving threats.

Book a Demo