Ryuk Ransomware: A Targeted Campaign Break-Down
2018-08-21 • Checkpoint •
https://research.checkpoint.com/ryuk-ransomware-targeted-campaign-break/
Check Point analyzed Ryuk as a targeted ransomware campaign that hit several enterprises worldwide and produced large ransom payments, with infections manually focused on critical systems after prior network mapping and credential collection. The researchers found strong code-level overlap between Ryuk and HERMES ransomware, including similar file-encryption logic, identical encrypted-file marker handling, shared exclusions such as Ahnlab and Microsoft folders, and comparable artifacts including window.bat, PUBLIC, and UNIQUE_ID_DO_NOT_REMOVE. HERMES had previously been used in the Far Eastern International Bank attack commonly attributed to Lazarus, but the report frames Ryuk attribution cautiously as either HERMES operators or another actor possessing HERMES source code. Ryuk’s dropper selected 32- or 64-bit payloads, killed many security, backup, database, and office-related processes and services, established Run-key persistence, and attempted process injection before encrypting files.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | cb0c1248d3899358a375888bb4e8f3fe | 2018-08-21 | 2018-08-21 |
| HASH | 8d3f68b16f0710f858d8c1d2c699260… | 2018-08-21 | 2018-08-21 |
| HASH | 1354ac0d5be0c8d03f4e3aba78d2223e | 2018-08-21 | 2018-08-21 |
| HASH | d348f536e214a47655af387408b4fca5 | 2018-08-21 | 2018-08-21 |
| HASH | 958c594909933d4c82e93c22850194aa | 2018-08-21 | 2018-08-21 |
| HASH | c0202cf6aeab8437c638533d14563d35 | 2018-08-21 | 2018-08-21 |
| HASH | 86c314bc2dc37ba84f7364acd5108c2b | 2018-08-21 | 2018-08-21 |
| HASH | 29340643ca2e6677c19e1d3bf351d654 | 2018-08-21 | 2018-08-21 |
| HASH | 5ac0f050f93f86e69026faea1fbb4450 | 2018-08-21 | 2018-08-21 |