logo

Examining the Ryuk Ransomware

ID: a8ac771d-5f75-5caa-86d4-dcd5e05e096b

STIX ID: report--a8ac771d-5f75-5caa-86d4-dcd5e05e096b

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-10-10

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabz report analyzes Ryuk ransomware: its distribution as a payload delivered by Emotet and TrickBot, OS-aware dropper behavior, persistence via Run registry key, process injection and termination of security/database services, deletion of shadow copies and backups via batch commands, and file encryption using per-file AES-256 with RSA-wrapped AES keys and a HERMES marker. The report notes Ryuk’s enterprise targeting and high ransom demands, describes ransom note behavior and dropped files (Public and UNIQUE_ID_DO_NOT_REMOVE), and includes MD5 indicators for observed samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.