Ryuk ransomware attack caused by student pirating software

ID theft
(Image credit: Future)

Security firm Sophos has revealed how using pirated software was the cause of a major ransomware attack that cost a major scientific organization a week’s work and a lot of money.

A student working at a European biomolecular research institute was allowed to use expensive data visualization software. However, he wanted a version of that software for his own device, but the license was most likely too expensive - so as a workaround, tried to install a cracked copy he found online. 

The crack triggered a malware warning from Microsoft Defender, which he not only ignored, but decided to disable the antivirus tool, as well as the firewall, instead. Fast-forward a few weeks later, and the incident response team from Sophos learned that the crack was actually info-stealing malware.

The info-stealer was in use by a malicious third-party for a few days, doing what it does best - gathering keystrokes, stealing browser cookies, clipboard data and such. Somewhere along the way, Sophos explained, it found the student’s access credentials for the institute’s network.

Once enough data was gathered, Ryuk ransomware was deployed. It encrypted all of the data it found on the network, and most likely demanded payment in cryptocurrency.

Old backup

While Sophos did not go into details how much money the operators asked for, or whether or not the institute paid the ransom, it did say that the organization lost a week’s worth of data, given that its backup wasn’t up to date.

The institute also suffered operational impact, as all computer and server files needed to be rebuilt from the ground up, before any data could be restored. 

“Perhaps the hardest lesson of all,” Sophos says, “was discovering that the attack and its impact could have been avoided with a less trusting and more robust approach to network access.”

It also said that the same group that placed the info-stealer probably wasn’t the same one that installed Ryuk. The most likely scenario is, once access was established, that it got sold on the dark web to the highest bidder.

Pirating software is not only illegal, but also dangerous, Sophos concluded.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
Representational image of a cybercriminal
Should ransomware payments be illegal?
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Scam alert
Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Latest in News
Garmin Instinct 3 next to the Apple Watch Ultra 2
New figures claim the smartwatch market just shrunk for the first time ever, and the Apple Watch Ultra 3 is to blame
Hitman: World of Assassination on PSVR 2.
Hitman: World of Assassination hits PSVR 2 soon, finally giving you a reason to dust off your headset
Hector Ayala sitting on a bed as he wears his White Tiger costume in Daredevil: Born Again season 1
Daredevil: Born Again episode 3's shocking final scene is a big misdirect, and I've got the evidence to back it up
A stressed employee looking over some graphs
UK workers are spending more than one day per week tracking down information
Vision Pro Metallica
Apple Vision Pro goes off to never never land with Metallica concert footage
Mufasa is joined by another lion, a monkey and a bird in this promotional image
Mufasa: The Lion King prowls onto Disney+ as it finally gets a streaming release date