Home > Today’s Crypto News
bitcoin
bitcoin

$107167.915651 USD

-1.23%

ethereum
ethereum

$2484.735224 USD

-0.65%

tether
tether

$1.000551 USD

0.03%

xrp
xrp

$2.227485 USD

1.25%

bnb
bnb

$657.234657 USD

0.38%

solana
solana

$153.359085 USD

0.76%

usd-coin
usd-coin

$1.000234 USD

0.03%

tron
tron

$0.279694 USD

1.12%

dogecoin
dogecoin

$0.164283 USD

-2.04%

cardano
cardano

$0.566559 USD

-0.46%

hyperliquid
hyperliquid

$39.355826 USD

-3.77%

bitcoin-cash
bitcoin-cash

$520.939018 USD

3.97%

sui
sui

$2.773602 USD

-2.77%

chainlink
chainlink

$13.247285 USD

-2.04%

unus-sed-leo
unus-sed-leo

$9.098882 USD

-0.71%

Ryuk Ransomware

What Is Ryuk Ransomware?

Ryuk ransomware is a ransomware attack. The Ryuk ransomware variant was originally discovered in August 2018 and since then it has managed to grow in visibility in order to become one of the most known as well as costliest ransomware variants of our time. This is due to the fact that, unlike early variations such as WannaCry, Ryuk is designed to be targeted. The design of this malware means that each of the victims has to receive the individual attention of the cybercriminals operating the malware. Ryuk is used in many targeted campaigns that have highly tailored infection vectors as well as high ransom demands. 

Discussing Ryuk even further, the ransomware focuses on quality over quantity when it comes to picking out its victims. A Ryuk infection starts with a targeted attack to infect an intended victim, which follows file encryption as well as an extremely large ransom demand by the Ryuk ransomware.

When we discuss targeted means, these include the use of tailored spear-phishing emails as well as the exploitation of compromised credentials that are used to remotely access systems through a Remote Desktop Protocol (RDP). 

A spear phishing email can carry Ryuk directly or be one of the first in a series of infections. Ryuk then uses a combination of encryption algorithms, such as an asymmetric algorithm known as AES-256 as well as an asymmetric algorithm known as RSA 4096. This means that Ryuk essentially encrypts a file with the symmetric algorithm and includes a copy of the symmetric encryption key encrypted with the RSA public key. When the victim pays for the ransom, the Ryuk operator will provide a copy of the corresponding RSA private key, which enables decryption for the symmetric encryption key where it is used on the encrypted files.