Ryuk Ransomware: A Targeted Campaign Break-Down

2018-08-21 Checkpoint

https://research.checkpoint.com/ryuk-ransomware-targeted-campaign-break/

Thumbnail for Ryuk Ransomware: A Targeted Campaign Break-Down

Check Point analyzed Ryuk as a targeted ransomware campaign that hit several enterprises worldwide and produced large ransom payments, with infections manually focused on critical systems after prior network mapping and credential collection. The researchers found strong code-level overlap between Ryuk and HERMES ransomware, including similar file-encryption logic, identical encrypted-file marker handling, shared exclusions such as Ahnlab and Microsoft folders, and comparable artifacts including window.bat, PUBLIC, and UNIQUE_ID_DO_NOT_REMOVE. HERMES had previously been used in the Far Eastern International Bank attack commonly attributed to Lazarus, but the report frames Ryuk attribution cautiously as either HERMES operators or another actor possessing HERMES source code. Ryuk’s dropper selected 32- or 64-bit payloads, killed many security, backup, database, and office-related processes and services, established Run-key persistence, and attempted process injection before encrypting files.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cb0c1248d3899358a375888bb4e8f3fe 2018-08-21 2018-08-21
HASH 8d3f68b16f0710f858d8c1d2c699260… 2018-08-21 2018-08-21
HASH 1354ac0d5be0c8d03f4e3aba78d2223e 2018-08-21 2018-08-21
HASH d348f536e214a47655af387408b4fca5 2018-08-21 2018-08-21
HASH 958c594909933d4c82e93c22850194aa 2018-08-21 2018-08-21
HASH c0202cf6aeab8437c638533d14563d35 2018-08-21 2018-08-21
HASH 86c314bc2dc37ba84f7364acd5108c2b 2018-08-21 2018-08-21
HASH 29340643ca2e6677c19e1d3bf351d654 2018-08-21 2018-08-21
HASH 5ac0f050f93f86e69026faea1fbb4450 2018-08-21 2018-08-21

Related Actors

Related Reports

« Back