New Ryuk Ransomware Sample Targets Webservers
ID: a97d4032-ad49-5b19-8020-9007c6d44324
STIX ID: report--a97d4032-ad49-5b19-8020-9007c6d44324
Feed Name: McAfee Labs Blog
Ryuk is a targeted ransomware family observed since 2018 that encrypts victims' files using AES-256 for file contents and RSA (2048/4096) to protect symmetric keys, demanding Bitcoin for decryption; infections commonly arise from spear-phishing, exploited public-facing apps, or via commodity malware loaders such as Emotet and TrickBot, and recent samples have targeted webservers and exhibit behaviors like printing multiple ransom notes. The report provides detection names, recommended defensive measures (patching, MFA, endpoint protection), MITRE technique mappings, and links to a full technical analysis and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
