{
  "family": "ryuk",
  "sample_count": 12,
  "category": "ransomware",
  "description": "Ryuk is a ransomware designed to target enterprise environments that, per MITRE ATT&CK, has been used in attacks since at least 2018 and shares code similarities with Hermes ransomware. It was frequently deployed as a final stage after access gained through TrickBot/Emotet infections and manual network reconnaissance, and is associated with high-ransom attacks on organizations including healthcare.",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Ryuk"
  ],
  "enrichment_level": "curated_sourced",
  "faq": [
    {
      "@type": "Question",
      "name": "What is Ryuk?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "A targeted ransomware aimed at enterprise environments, used in attacks since at least 2018."
      }
    },
    {
      "@type": "Question",
      "name": "What is Ryuk related to?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "MITRE notes it shares code similarities with Hermes ransomware."
      }
    },
    {
      "@type": "Question",
      "name": "How did Ryuk attacks usually start?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Frequently through prior TrickBot/Emotet infections that gave attackers a foothold to spread and deploy the ransomware."
      }
    },
    {
      "@type": "Question",
      "name": "Who was commonly targeted by Ryuk?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Enterprises and public-sector organizations, including healthcare, where downtime pressure could push victims to pay large ransoms."
      }
    },
    {
      "@type": "Question",
      "name": "Is paying the Ryuk ransom advisable?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Security guidance generally discourages paying ransoms. Restore from clean, tested backups and engage professional incident response instead."
      }
    },
    {
      "@type": "Question",
      "name": "How can organizations defend against Ryuk?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "Block the precursor infections (phishing, TrickBot/Emotet), segment networks, limit privileged access, and maintain tested offline backups."
      }
    },
    {
      "@type": "Question",
      "name": "Where is the authoritative reference?",
      "acceptedAnswer": {
        "@type": "Answer",
        "text": "MITRE ATT&CK's Ryuk entry (S0446), linked on this page."
      }
    }
  ],
  "faq_count": 7,
  "mitre_attack": [
    "T1566.001",
    "T1486",
    "T1490",
    "T1059.003"
  ],
  "cisa_advisory": "https://www.cisa.gov/news-events/alerts/2020/10/28/ransomware-activity-targeting-healthcare-and-public-health-sector",
  "last_updated": "2026-06-09",
  "sources": [
    {
      "name": "MITRE ATT&CK: Ryuk (S0446)",
      "url": "https://attack.mitre.org/software/S0446"
    }
  ],
  "mitre_url": "https://attack.mitre.org/software/S0446",
  "threat_actors": [
    "Wizard Spider"
  ],
  "target_industries": [
    "Healthcare",
    "Government",
    "Enterprise"
  ],
  "target_geographies": [
    "North America",
    "EMEA"
  ],
  "motivation": "Financial Extortion"
}