Home > Today’s Crypto News
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

Ryuk Ransomware

What Is Ryuk Ransomware?

Ryuk ransomware is a ransomware attack. The Ryuk ransomware variant was originally discovered in August 2018 and since then it has managed to grow in visibility in order to become one of the most known as well as costliest ransomware variants of our time. This is due to the fact that, unlike early variations such as WannaCry, Ryuk is designed to be targeted. The design of this malware means that each of the victims has to receive the individual attention of the cybercriminals operating the malware. Ryuk is used in many targeted campaigns that have highly tailored infection vectors as well as high ransom demands. 

Discussing Ryuk even further, the ransomware focuses on quality over quantity when it comes to picking out its victims. A Ryuk infection starts with a targeted attack to infect an intended victim, which follows file encryption as well as an extremely large ransom demand by the Ryuk ransomware.

When we discuss targeted means, these include the use of tailored spear-phishing emails as well as the exploitation of compromised credentials that are used to remotely access systems through a Remote Desktop Protocol (RDP). 

A spear phishing email can carry Ryuk directly or be one of the first in a series of infections. Ryuk then uses a combination of encryption algorithms, such as an asymmetric algorithm known as AES-256 as well as an asymmetric algorithm known as RSA 4096. This means that Ryuk essentially encrypts a file with the symmetric algorithm and includes a copy of the symmetric encryption key encrypted with the RSA public key. When the victim pays for the ransom, the Ryuk operator will provide a copy of the corresponding RSA private key, which enables decryption for the symmetric encryption key where it is used on the encrypted files.