logo

New Ryuk Ransomware Sample Targets Webservers

ID: a97d4032-ad49-5b19-8020-9007c6d44324

STIX ID: report--a97d4032-ad49-5b19-8020-9007c6d44324

Feed Name: McAfee Labs Blog

Threat Score
80/100

Date Published: 2021-07-07

Date Updated: 2026-04-28

Author: Marc Elias

...
...

Ryuk is a targeted ransomware family observed since 2018 that encrypts victims' files using AES-256 for file contents and RSA (2048/4096) to protect symmetric keys, demanding Bitcoin for decryption; infections commonly arise from spear-phishing, exploited public-facing apps, or via commodity malware loaders such as Emotet and TrickBot, and recent samples have targeted webservers and exhibit behaviors like printing multiple ransom notes. The report provides detection names, recommended defensive measures (patching, MFA, endpoint protection), MITRE technique mappings, and links to a full technical analysis and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.