Ryuk ransomware targets big businesses

(Image credit: Image Credit: Carlos Amarillo / Shutterstock)

While ransomware attacks generally infect all possible victims, a recently discovered ransomware group has brought in almost $4m since August by installing its malicious encryption software on high value targets that have previously been infected.

The ransomware, known as Ryuk, infects large enterprises days, weeks or even a year after they were previously infected by separate malware.

In most cases, firms are first infected with a powerful trojan called Trickbot. However, smaller organisations infected by Trickbot rarely suffer as much as their larger counterparts.

The security firm CrowdStrike calls the approach used by Ryuk “big-game hunting” and so far its tactics have allowed cybercriminals to generate $3.7m worth of Bitcoin from 52 transactions since August.

Dwell time

What sets Ryuk apart from other strains of ransomware is its dwell time. During the period between the initial infection and the installation of the ransomware, cybercriminals have plenty of time to perform reconnaissance inside an infected network which lets them maximise the damage done by targeting critical network systems after first obtaining their passwords.

This tactic, while uncommon, is also used by the SamSam ransomware that infected city networks in Atlanta, Baltimore's 911 system and Boeing among others. Federal prosecutors revealed that SamSam's operators brought in over $6m in ransom payments while causing over $30m in damages. 

Security firms FireEye and CrowdStrike have both downplayed reports that Ryuk was created by North Korean actors. CrowdStrike discovered evidence that the new strain of ransomware might actually originate from Russia.

Researchers at FireEye shed further light on Ryuk, saying:

“Throughout 2018, FireEye observed an increasing number of cases where ransomware was deployed after the attackers gained access to the victim organization through other methods, allowing them to traverse the network to identify critical systems and inflict maximum damage. SamSam operations, which date back to late 2015, were arguably the first to popularize this methodology, and [Ryuk] is an example of its growing popularity with threat actors. FireEye Intelligence expects that these operations will continue to gain traction throughout 2019 due the success these intrusion operators have had in extorting large sums from victim organizations.” 

Via Ars Technica

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Latest in News
Rainbow Six Siege X promotional art.
The Tom Clancy's Rainbow Six Siege X 6v6 mode might finally pull me away from Black Ops 6
Silent Hill f
Silent Hill f will present players with 'a beautiful yet terrifying choice', and I can't wait to see what it is
Google Chromecast 2
Google is finally rolling out a fix for broken Chromecasts – just as new bugs appear on the Chromecast with Google TV
Garmin Instinct 3 in Neotropic Green
"I'm an idiot": Garmin user reveals how fixing one setting completely changed their training after months of making no progress
The main battle pass characters in Fortnite Lawless, including Midas, Sub Zero and a large wolf-man
You'll finally be able to play Fortnite on Windows 11 Arm-powered laptops as Epic Games partners with Qualcomm
DeepSeek on an iPhone
OpenAI calls on US government to ban DeepSeek, calling it ‘state-subsidized’ and ‘state-controlled’