logo

A Deep Dive into the Ryuk Ransomware Attack Chain and Its Impact

ID: 8960612f-3e21-568c-89e7-6ae15c2f5feb

STIX ID: report--8960612f-3e21-568c-89e7-6ae15c2f5feb

Feed Name: Resources-2

Threat Score
76/100

Date Published: 2025-08-07

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren Hacıoğlu)

...
...

This report provides a technical analysis of the Ryuk ransomware (attributed to Wizard Spider), mapping its attack chain to the MITRE ATT&CK framework. It explains initial access via phishing and secondary loaders (Emotet/TrickBot), discovery and credential theft techniques (adfind, nltest, systeminfo, Rubeus kerberoasting), privilege escalation and lateral movement (PowerView/PowerLine), defense-evasion steps (PowerShell policy changes, WMI queries), and impact actions (disabling backups, deleting shadow copies, AES/RSA encryption). The document also shows Picus simulation commands used to emulate Ryuk behaviors and validate defensive controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.