Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
73
Global rank
83 infographic chevron month
Month rank
61 infographic chevron week
Week rank
0
IOCs

Ryuk is a Ransomware — a type of malware that encrypts files of the victim and restores access in exchange for a ransom payment. Operating since 2018, Ryuk has been continually carrying out successful targeted attacks on organizations, netting operators millions of dollars throughout its lifetime.

Ransomware
Type
Unknown
Origin
1 August, 2018
First seen
27 August, 2026
Last seen

How to analyze Ryuk with ANY.RUN

Type
Unknown
Origin
1 August, 2018
First seen
27 August, 2026
Last seen

IOCs

IP addresses
154.91.34.165
139.99.85.213
75.119.193.253
45.141.233.69
149.154.166.110
188.114.97.3
208.95.112.1
185.121.177.177
132.148.178.5
142.251.20.94
158.101.44.242
213.180.204.127
74.120.9.121
217.78.234.145
193.122.130.0
176.65.144.23
188.114.96.3
74.120.8.6
142.251.14.120
185.156.72.2
Hashes
718578ecb833c4526630488cb9c7f41108f66bba0c54e63b636cc9911339ca63
a7de5177c68a64bd48b36d49e2853799f4ebcfa8e4761f7cc472f333dc5f65cf
edb55f2f05a6f02ab2bf5c78aa4f261155a514d8d178c0b7e698f589f4381349
2fca1f29b73dd5b4159fa1eb16e69276482f5224ba7d2219a547039129a51f0e
34baf1e4733ef94b1303dc5d283e165b32a3a5804b07e7f8a03352100e7d5b78
151dbc44177a314fb720ed909ead366760b69c69daf676fea52248ac7ad71d9a
caafea31074ba909ec57c9dcdd1b1c0256e5626939cc768b8a041fe42762e230
b733f9351938ad36c8e733639f581f4bbd70840874e6ef05101f8e1d8ccdbd7f
e90f2cd8ca1d0feb9a8c73908ca021b085816a9f469c4b4ca07c12f1996c7a59
59bc5272a4a2940ef7aad07c960200135dd9909b3150c3322f0e62c1e40709b6
aaca1b27a5186df31e60ab0bcfe35d411e03fd7cd069fafb92314947fd92f256
bb6a3e1dd1c5f113fc353c1820b404fcdd3ad705c0d0febf8a10d3618c4cf226
210f1b214eccde9e148072a10fc0e263fe6a443341be4dc9630c47bc84796101
b7771ac44ab547a772787c6db58afcab0e603e8f9127f3a486a7792ee3e04a90
1cc5c7a5d650cbc028b38cf50ebb4a72ee807e3ba7f26941df0f6a10e776cf95
6b9cae182ec085bd8cc7d52de0fd175ce7cb0186119c8e6e85230fcf9d10e318
411958454cc7b99de0c5b4b03dfb232bafd9a4c1c0b078791eb2c6ae24b1b088
8743b4febe9f3c99e1c5b647255e6367ddac8580e1388feaf78e0bc84fbb1776
eee6e710161a3aa8488fb4c1f118b43fa5c377ecdedffaae78a81865f16cf288
eb2acbbda0da676b8e12af944db41f916380f7eaf70818fd70626d3d6b1564c2
Domains
mail.dhakahome.com
api.telegram.org
google.com
www.dontlookhere.com
checkip.dyndns.org
dontlookhere.com
cloud-api.yandex.net
s3.timeweb.cloud
gstatic.com
ip-api.com
reallyfreegeoip.org
api.pcloud.com
watson.microsoft.com
wizz.infinitycloud.org
api.ipify.org
client.wns.windows.com
www.bing.com
ocsp.digicert.com
crl.microsoft.com
go.microsoft.com
URLs
http://ip-api.com/json/
https://gstatic.com/generate_204
http://ip-api.com/line/?fields=hosting
https://api.pcloud.com/listfolder?path=/
https://cloud-api.yandex.net/v1/disk/resources?path=/&limit=500
http://checkip.dyndns.org/
https://reallyfreegeoip.org/xml/141.11.36.2
https://api.telegram.org/bot/sendmessage?chat_id=&text=%20%0d%0a%0d%0apc%20name:user-pc%0d%0adate%20and%20time:%208/27/2026%20/%204:42:37%20am%0d%0acountry%20name:%20%0d%0a%5b%20user-pc%20clicked%20on%20the%20file%20if%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5d
https://api.telegram.org/bot7950066405:aae5kuvk04df6lzjfoe-yzt3f12hjhmziqg/senddocument?chat_id=-4703613545&caption=%20pc%20name:%20admin%20%7c%20/%20vip%20recovery%20%5c%0d%0a%0d%0apw%20%7c%20admin%20%7c%20vip%20recovery
http://www.dontlookhere.com/blog
https://dontlookhere.com/
https://dontlookhere.com/blog/
http://dontlookhere.com/blog/
https://reallyfreegeoip.org/xml/141.11.36.18
https://api.telegram.org/bot/sendmessage?chat_id=&text=%20%0d%0a%0d%0apc%20name:user-pc%0d%0adate%20and%20time:%208/27/2026%20/%204:41:42%20am%0d%0acountry%20name:%20%0d%0a%5b%20user-pc%20clicked%20on%20the%20file%20if%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5d
https://reallyfreegeoip.org/xml/194.32.120.12
https://api.telegram.org/bot/sendmessage?chat_id=&text=%20%0d%0a%0d%0apc%20name:user-pc%0d%0adate%20and%20time:%208/27/2026%20/%204:34:32%20am%0d%0acountry%20name:%20%0d%0a%5b%20user-pc%20clicked%20on%20the%20file%20if%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5d
https://watson.microsoft.com/stageone/generic/clr20r3/vcf1h4noxuy1beu2mx1ct13f0geplflx/0_0_0_0/6281b36a/mscorlib/4_8_4110_0/5de6d97a/1693/ca/system_io_filenotfoundexception.htm?lcid=1033&os=6.1.7601.2.00010100.1.0.48.17514&sm=dell&spn=dell&bv=dell&mid=3ade2c42-4ab9-49b7-b142-be9aeea69063
https://watson.microsoft.com/dw/generictwo.asp?eventtype=clr20r3&p1=vcf1h4noxuy1beu2mx1ct13f0geplflx&p2=0.0.0.0&p3=6281b36a&p4=mscorlib&p5=4.8.4110.0&p6=5de6d97a&p7=1693&p8=ca&p9=system.io.filenotfoundexception&lcid=1033&os=6.1.7601.2.00010100.1.0.48.17514&sm=dell&spn=dell&bv=dell&mid=3ade2c42-4ab9-49b7-b142-be9aeea69063
https://api.telegram.org/bot/sendmessage?chat_id=&text=%20%0d%0a%0d%0apc%20name:user-pc%0d%0adate%20and%20time:%208/27/2026%20/%204:30:57%20am%0d%0acountry%20name:%20%0d%0a%5b%20user-pc%20clicked%20on%20the%20file%20if%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5d
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2658
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7601
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10652
comments 0

What is Ryuk Ransomware?

Ryuk is a highly targeted Ransomware — a malware that encrypts files of its victims and demands a payment to restore access to information. Ryuk was first identified in august 2018 and remains active to this day. It attacks newspapers, public institutions, banks, restaurants, and other businesses.

Although it is not considered to be the most high-tech malware in its class, Ryuk Ransomware is very successful. In fact, according to the FBI, it is the number one Ransomware in terms of completed ransom payments.

Thanks to a highly targeted approach to distribution, the malware has managed to infiltrate thousands of PCs and yielded attackers millions of US dollars. In fact, some of the ransoms paid by organizations reach 400,000 US dollars.

Despite not being the most cutting-edge, Ryuk is not be toyed with.

General description of Ryuk Ransomware

The success of Ryuk Ransomware likely can be tied to its selective attack approach. While a lot of malicious programs nowadays are starting to move away from widespread email spam campaigns, Ryuk malware goes another step forward. Its attacks not only use collected information about the victim for initial payload delivery but even the encryption process is being tailored to each victim, targeting the most valuable files.

This fact indicates that operators behind Ryuk malware carefully study each victim and perform expensive scouting and network mapping.

On top of that, Ryuk Ransomware operators are flexible with Ransom demands and adjust not only the ransom amount but also the ransom note context. At least two variants of the ransom note were observed since Ryuk Ransomware became active in 2018. One was well-written, almost polite, and quite long, used in an attack on a large organization with a high ransom demand. The use of a second variant was recorded in the majority of attacks on smaller victims. It is much shorter and uses more blunt and straightforward wording.

Some researchers expressed an opinion that this variation in ransom notes may indicate that the Ryuk Ransomware team uses two separate attack approaches with different complexity.

Preparing for attacks very carefully and learning about each victim allowed the Ryuk malware team to carry out successful campaigns with huge ransom demands. According to some data the average demanded ransom amount is around 674,039 US dollars, while the highest recorded ransom demand was over a million US dollars.

It is not exactly obvious who stands behind this Ransomware. Some evidence and code similarities to another Ransomware called Hermes point towards a North Korean APT, Lazarus Group. However, this is not hard evidence, considering that a sample of Hermes could have fallen into the hands of another criminal and serve as a base for Ryuk's development.

Other reports based on more recent data link Ryuk Ransomware to a Russian criminal group named WIZARD SPIDER, which is known for its work with TrickBot malware. For example, cybersecurity researchers found documents that contained Russian words in filenames while investigating a compromised network, that fell victim to Ryuk. This suggests that the WIZARD SPIDER hypothesis is more likely than the Korean connection.

Additionally, Ryuk checks the keyboard language and terminates execution if it detects Russian, Belarus, or Ukrainian languages, which can be used as a killswitch. This kind of behavior is typical for a malicious program that originated on an ex-USSR territory.

Ryuk malware analysis

A video recorded in the ANY.RUN malware hunting service allows us to watch the execution process of Ryuk malware in action.

ryuk_ransomware_text_report

Figure 1: Displays the text report generated by the ANY.RUN malware hunting service

ryuk_ransomware_ransom_note_variant

Figure 2: One of the variants of the Ryuk ransom note

ryuk_ransomware_ransom_note_variant

Figure 3: One of the variants of the Ryuk ransom note

ryuk_ransomware_ransom_note_variant

Figure 4: One of the variants of the Ryuk ransom note

Ryuk Ransomware execution process

The execution process of Ryuk is not much different from other ransomware such as WannaCry or Netwalker. After the executable file makes its way into an infected system and runs, the main malicious activity begins. Like many other ransomware families, Ryuk deletes shadow copy files. It also stops processes from the hardcoded list. Like other malware of this type, it creates a text or HTML file with a ransom note.

Ryuk Ransomware distribution

In many instances of confirmed Ryuk malware infections, the victim’s machine was also infiltrated by TrickBot. This led researchers to believe that Ryuk Ransomware makes its way into computers with TrickBot, which in turn is usually delivered through mail spam or with a Trojan Emotet.

This distribution method further supports the theory that Ryuk is operated by WIZARD SPIDER.

It is a known fact that the organization associated with Emotet is MUMMY SPIDER, which has been connected with the WIZARD gang in the past.

Conclusion

A high degree of personalization and a careful approach to victim selection made Ryuk Ransomware exceptionally successful. To date, malware operators behind the Ransomware have already collected over 64 million US dollars in payments, according to the FBI reports. The recipe for success is simple but solid — attackers choose successful businesses, that are definitely capable of paying the ransom and quite often will lose more money if they withhold the payment since their operation becomes completely frozen by the inability to access the most vital information.

Unfortunately, this means that a lot of the victims gave in to the demands of the criminals and unwillingly supported future attacks. It is a known fact, that besides capturing Ransomware operators, arguably the most important thing to do — is not paying the ransom.

Sadly, with the success that Ryuk malware has, it is unrealistic to hope that the attacks will stop in the near future. Therefore, the best thing to do now is to study this malware and prepare defense measures against it. Thankfully, ANY.RUN malware hunting service gives cyber teams all the tools they need to analyze Ryuk Ransomware in a secure online interactive sandbox.

HAVE A LOOK AT

Tycoon 2FA screenshot
Tycoon 2FA
tycoon
Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
Gunra screenshot
Gunra
gunra
Gunra ransomware, a financially motivated threat actor that emerged in April 2025, deploys double-extortion tactics to encrypt victims' data and threaten leaks of exfiltrated information, primarily targeting Windows and Linux systems across healthcare, manufacturing, and other sectors worldwide.
Read More
SolarisLoader screenshot
SolarisLoader
solaris
SolarisLoader is a malware loader designed to neutralize security infrastructure before deploying high-risk secondary payloads. It utilizes a "Bring Your Own Vulnerable Driver" technique to gain kernel-level access and terminate antivirus processes. To remain undetected, the malware patches internal Windows monitoring interfaces and isolates the machine from security updates. Finally, it establishes a resilient three-layer persistence mechanism involving scheduled tasks, registry backups, and a watchdog component.
Read More
Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More
Play Ransomware screenshot
Play aka PlayCrypt ransomware group has been successfully targeting corporations, municipal entities, and infrastruction all over the world for about three years. It infiltrates networks via software vulnerabilities, phishing links and compromised websites. The ransomware abuses Windows system services to evade detection and maintain persistence. Play encrypts user files and steals sensitive data while demanding a ransom.
Read More