{"id":36757,"date":"2025-06-30T12:15:59","date_gmt":"2025-06-30T12:15:59","guid":{"rendered":"https:\/\/fidelissecurity.com\/?post_type=cybersecurity-101&#038;p=36757"},"modified":"2025-08-07T17:34:56","modified_gmt":"2025-08-07T17:34:56","slug":"ryuk-ransomware","status":"publish","type":"cybersecurity-101","link":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/","title":{"rendered":"What is Ryuk: Complete Guide to the Notorious Ransomware"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"36757\" class=\"elementor elementor-36757\" data-elementor-settings=\"{&quot;ha_cmc_init_switcher&quot;:&quot;no&quot;}\" data-elementor-post-type=\"cybersecurity-101\">\n\t\t\t\t<div class=\"elementor-element elementor-element-05f1823 e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"05f1823\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0bda647 elementor-widget elementor-widget-text-editor\" data-id=\"0bda647\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">In September 2020, Universal Health Services faced a devastating cyberattack that forced over 400 medical facilities across the United States and United Kingdom to revert to paper-based procedures. This wasn\u2019t just another ransomware attack &#8211; it was <b><i>Ryuk<\/i><\/b>, one of the most sophisticated and financially devastating ransomware families ever created.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Since its emergence in August 2018, Ryuk has distinguished itself from other ransomware through its targeted approach, focusing on \u201cbig game hunting\u201d rather than indiscriminate attacks. Unlike most <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/threats-and-vulnerabilities\/ransomware-attacks\/\">ransomware<\/a> families that cast wide nets hoping to catch numerous small victims, ryuk ransomware specifically targets large organizations with the resources to pay substantial ransom payments.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Understanding what Ryuk is and how it operates has become crucial for organizations worldwide. This comprehensive guide will explore everything you need to know about this notorious malware, from its technical capabilities to prevention strategies that can protect your organization from becoming the next victim.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-faeaf5e e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"faeaf5e\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-60502d2 elementor-widget elementor-widget-heading\" data-id=\"60502d2\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"understanding\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Understanding Ryuk Ransomware<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1947e30 elementor-widget elementor-widget-text-editor\" data-id=\"1947e30\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Ryuk is a highly targeted ransomware variant derived from the earlier hermes ransomware family, but it has evolved far beyond its predecessor\u2019s capabilities. Unlike broad-spectrum malware that attempts to infect as many systems as possible, Ryuk uses \u201cbig game hunting\u201d tactics to target high-value organizations including hospitals, government agencies, universities, and large corporations.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">What makes Ryuk particularly dangerous is its ability to encrypt not just local system files, but also network drives and resources accessible to the infected machine. The ransomware actively seeks to disrupt backup and recovery mechanisms by deleting Windows Volume Shadow Service (VSS) shadow copies, making it nearly impossible for victims to restore their data without paying the ransom.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Files encrypted by Ryuk typically receive file extensions like .ryk or .RYK, making them completely inaccessible without the proper decryption key. The malware creates ransom notes named \u201cRyukReadMe.txt\u201d in every affected directory, containing instructions for contacting the ryuk attackers and payment details.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The sophistication of ryuk ransomware extends to its operational security. The malware is programmed to avoid infecting systems configured with Russian, Ukrainian, or Belarusian language settings, strongly indicating the geographic preferences and potential nationality of its operators.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-71f41f9 elementor-widget elementor-widget-image\" data-id=\"71f41f9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Analysis-500x500.webp\" title=\"Ryuk Ransomware Analysis\" alt=\"Ryuk Ransomware Analysis\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-4448567 e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"4448567\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-91c4799 elementor-widget elementor-widget-heading\" data-id=\"91c4799\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"origin-and-attribution\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Origins and Attribution<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b3da4cc elementor-widget elementor-widget-text-editor\" data-id=\"b3da4cc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">First detected in August 2018, Ryuk emerged as a heavily modified version of the older hermes ransomware. The transformation wasn\u2019t merely cosmetic &#8211; ryuk operators had fundamentally reimagined how ransomware could be deployed for maximum impact and profit.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The name \u201cRyuk\u201d references a death god character from the popular Japanese manga and anime series \u201cDeath Note.\u201d This choice reflects the operators\u2019 attention to impactful branding and cultural references, suggesting a level of sophistication that extends beyond mere technical capabilities.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">WIZARD SPIDER, a Russian-speaking cybercriminal organization, is attributed as the primary operator behind ryuk attacks. This group previously operated a subgroup called GRIM SPIDER, which was later merged under the WIZARD SPIDER umbrella. The organization has demonstrated remarkable adaptability, continuously evolving their tactics and incorporating new techniques to maintain their effectiveness.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The attribution to WIZARD SPIDER is supported by several technical and operational indicators. Beyond the language avoidance mentioned earlier, the group\u2019s command and control infrastructure, malware distribution methods, and tactical patterns all point to a highly organized criminal enterprise with significant resources and technical expertise.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c84cb1 elementor-widget elementor-widget-image\" data-id=\"6c84cb1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"850\" height=\"810\" src=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Origins-and-Attribution.webp\" class=\"attachment-full size-full wp-image-36760\" alt=\"\" srcset=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Origins-and-Attribution.webp 850w, https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Origins-and-Attribution-300x286.webp 300w, https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Origins-and-Attribution-768x732.webp 768w\" sizes=\"(max-width: 850px) 100vw, 850px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d1b9dbe elementor-widget elementor-widget-text-editor\" data-id=\"d1b9dbe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW184723240 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW184723240 BCX8\">Intelligence agencies and cybersecurity researchers have tracked WIZARD SPIDER\u2019s activities across multiple campaigns, revealing a group that <\/span><span class=\"NormalTextRun SCXW184723240 BCX8\">operates<\/span><span class=\"NormalTextRun SCXW184723240 BCX8\"> with the precision and planning typically associated with nation-state actors, despite their purely criminal motivations.<\/span><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-774c248 e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"774c248\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1239186b e-con-full e-ecs-flex e-flex e-con e-child\" data-id=\"1239186b\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-225ff5a9 elementor-widget elementor-widget-heading\" data-id=\"225ff5a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Don\u2019t Let Ryuk Win: Outsmart Ransomware with Multi-Layered XDR<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1401da9b elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"1401da9b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"30\" height=\"32\" viewBox=\"0 0 30 32\" fill=\"none\"><path d=\"M28.4233 16.5056C28.3177 16.1761 28.3177 15.8209 28.4233 15.4913L29.4568 12.3171C29.6744 11.6419 29.4344 10.8996 28.8585 10.4836L26.1578 8.51886C25.8794 8.31727 25.6683 8.02927 25.5627 7.69972L24.5291 4.52227C24.3115 3.84711 23.6811 3.38952 22.9676 3.38952H19.6302C19.2846 3.38952 18.9454 3.28074 18.6638 3.07594L15.9632 1.11445C15.3904 0.69525 14.6096 0.69525 14.0369 1.11445L11.333 3.07594C11.0546 3.28074 10.7154 3.38952 10.3699 3.38952H7.02926C6.31887 3.38952 5.68851 3.84711 5.4709 4.52548L4.43736 7.69972C4.33174 8.02927 4.12058 8.31727 3.839 8.52206L1.14152 10.4836C0.565577 10.8996 0.32559 11.6419 0.543196 12.3171L1.57673 15.4913C1.68232 15.8209 1.68232 16.1761 1.57673 16.5056L0.543196 19.6831C0.32559 20.3582 0.565577 21.1006 1.14152 21.5166L3.8422 23.4781C4.12058 23.6829 4.32858 23.9708 4.43736 24.3004L5.4677 27.4746C5.68851 28.153 6.31887 28.6106 7.02926 28.6106H10.3699C10.7154 28.6106 11.0514 28.7194 11.333 28.921L14.0369 30.8857C14.6096 31.3048 15.3904 31.3048 15.9632 30.8857L18.667 28.921C18.9454 28.7194 19.2846 28.6106 19.6302 28.6106H22.9708C23.6811 28.6106 24.3115 28.153 24.5291 27.4746L25.5627 24.3004C25.6683 23.9708 25.8794 23.6829 26.1578 23.4781L28.8585 21.5166C29.4344 21.1006 29.6744 20.3582 29.4568 19.6831L28.4233 16.5056ZM21.7132 12.8418C21.7132 13.2642 21.5468 13.661 21.2493 13.9586L14.9392 20.2654C14.6544 20.5502 14.2512 20.7134 13.8289 20.7134C13.4065 20.7134 13.0001 20.5502 12.7153 20.2654L8.74432 16.3008C8.13318 15.6897 8.13318 14.6913 8.74112 14.0738C9.33953 13.4754 10.3795 13.4754 10.9746 14.0706L13.8257 16.9216L19.019 11.7283C19.6173 11.1395 20.6605 11.1395 21.2493 11.7283C21.5468 12.0259 21.7132 12.4227 21.7132 12.8418Z\" fill=\"url(#paint0_linear_227_654)\"><\/path><defs><linearGradient id=\"paint0_linear_227_654\" x1=\"15\" y1=\"0.800049\" x2=\"15\" y2=\"31.2\" gradientUnits=\"userSpaceOnUse\"><stop stop-color=\"#E55E06\"><\/stop><stop offset=\"1\" stop-color=\"#C00000\"><\/stop><\/linearGradient><\/defs><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Key ransomware trends &amp; attack paths <\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"30\" height=\"32\" viewBox=\"0 0 30 32\" fill=\"none\"><path d=\"M28.4233 16.5056C28.3177 16.1761 28.3177 15.8209 28.4233 15.4913L29.4568 12.3171C29.6744 11.6419 29.4344 10.8996 28.8585 10.4836L26.1578 8.51886C25.8794 8.31727 25.6683 8.02927 25.5627 7.69972L24.5291 4.52227C24.3115 3.84711 23.6811 3.38952 22.9676 3.38952H19.6302C19.2846 3.38952 18.9454 3.28074 18.6638 3.07594L15.9632 1.11445C15.3904 0.69525 14.6096 0.69525 14.0369 1.11445L11.333 3.07594C11.0546 3.28074 10.7154 3.38952 10.3699 3.38952H7.02926C6.31887 3.38952 5.68851 3.84711 5.4709 4.52548L4.43736 7.69972C4.33174 8.02927 4.12058 8.31727 3.839 8.52206L1.14152 10.4836C0.565577 10.8996 0.32559 11.6419 0.543196 12.3171L1.57673 15.4913C1.68232 15.8209 1.68232 16.1761 1.57673 16.5056L0.543196 19.6831C0.32559 20.3582 0.565577 21.1006 1.14152 21.5166L3.8422 23.4781C4.12058 23.6829 4.32858 23.9708 4.43736 24.3004L5.4677 27.4746C5.68851 28.153 6.31887 28.6106 7.02926 28.6106H10.3699C10.7154 28.6106 11.0514 28.7194 11.333 28.921L14.0369 30.8857C14.6096 31.3048 15.3904 31.3048 15.9632 30.8857L18.667 28.921C18.9454 28.7194 19.2846 28.6106 19.6302 28.6106H22.9708C23.6811 28.6106 24.3115 28.153 24.5291 27.4746L25.5627 24.3004C25.6683 23.9708 25.8794 23.6829 26.1578 23.4781L28.8585 21.5166C29.4344 21.1006 29.6744 20.3582 29.4568 19.6831L28.4233 16.5056ZM21.7132 12.8418C21.7132 13.2642 21.5468 13.661 21.2493 13.9586L14.9392 20.2654C14.6544 20.5502 14.2512 20.7134 13.8289 20.7134C13.4065 20.7134 13.0001 20.5502 12.7153 20.2654L8.74432 16.3008C8.13318 15.6897 8.13318 14.6913 8.74112 14.0738C9.33953 13.4754 10.3795 13.4754 10.9746 14.0706L13.8257 16.9216L19.019 11.7283C19.6173 11.1395 20.6605 11.1395 21.2493 11.7283C21.5468 12.0259 21.7132 12.4227 21.7132 12.8418Z\" fill=\"url(#paint0_linear_227_654)\"><\/path><defs><linearGradient id=\"paint0_linear_227_654\" x1=\"15\" y1=\"0.800049\" x2=\"15\" y2=\"31.2\" gradientUnits=\"userSpaceOnUse\"><stop stop-color=\"#E55E06\"><\/stop><stop offset=\"1\" stop-color=\"#C00000\"><\/stop><\/linearGradient><\/defs><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">How Fidelis Elevate\u00ae XDR spots Ryuk-like behavior <\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"30\" height=\"32\" viewBox=\"0 0 30 32\" fill=\"none\"><path d=\"M28.4233 16.5056C28.3177 16.1761 28.3177 15.8209 28.4233 15.4913L29.4568 12.3171C29.6744 11.6419 29.4344 10.8996 28.8585 10.4836L26.1578 8.51886C25.8794 8.31727 25.6683 8.02927 25.5627 7.69972L24.5291 4.52227C24.3115 3.84711 23.6811 3.38952 22.9676 3.38952H19.6302C19.2846 3.38952 18.9454 3.28074 18.6638 3.07594L15.9632 1.11445C15.3904 0.69525 14.6096 0.69525 14.0369 1.11445L11.333 3.07594C11.0546 3.28074 10.7154 3.38952 10.3699 3.38952H7.02926C6.31887 3.38952 5.68851 3.84711 5.4709 4.52548L4.43736 7.69972C4.33174 8.02927 4.12058 8.31727 3.839 8.52206L1.14152 10.4836C0.565577 10.8996 0.32559 11.6419 0.543196 12.3171L1.57673 15.4913C1.68232 15.8209 1.68232 16.1761 1.57673 16.5056L0.543196 19.6831C0.32559 20.3582 0.565577 21.1006 1.14152 21.5166L3.8422 23.4781C4.12058 23.6829 4.32858 23.9708 4.43736 24.3004L5.4677 27.4746C5.68851 28.153 6.31887 28.6106 7.02926 28.6106H10.3699C10.7154 28.6106 11.0514 28.7194 11.333 28.921L14.0369 30.8857C14.6096 31.3048 15.3904 31.3048 15.9632 30.8857L18.667 28.921C18.9454 28.7194 19.2846 28.6106 19.6302 28.6106H22.9708C23.6811 28.6106 24.3115 28.153 24.5291 27.4746L25.5627 24.3004C25.6683 23.9708 25.8794 23.6829 26.1578 23.4781L28.8585 21.5166C29.4344 21.1006 29.6744 20.3582 29.4568 19.6831L28.4233 16.5056ZM21.7132 12.8418C21.7132 13.2642 21.5468 13.661 21.2493 13.9586L14.9392 20.2654C14.6544 20.5502 14.2512 20.7134 13.8289 20.7134C13.4065 20.7134 13.0001 20.5502 12.7153 20.2654L8.74432 16.3008C8.13318 15.6897 8.13318 14.6913 8.74112 14.0738C9.33953 13.4754 10.3795 13.4754 10.9746 14.0706L13.8257 16.9216L19.019 11.7283C19.6173 11.1395 20.6605 11.1395 21.2493 11.7283C21.5468 12.0259 21.7132 12.4227 21.7132 12.8418Z\" fill=\"url(#paint0_linear_227_654)\"><\/path><defs><linearGradient id=\"paint0_linear_227_654\" x1=\"15\" y1=\"0.800049\" x2=\"15\" y2=\"31.2\" gradientUnits=\"userSpaceOnUse\"><stop stop-color=\"#E55E06\"><\/stop><stop offset=\"1\" stop-color=\"#C00000\"><\/stop><\/linearGradient><\/defs><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Best practices for early detection &amp; fast response <\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c4b3bc9 elementor-widget elementor-widget-button\" data-id=\"c4b3bc9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/fidelissecurity.com\/resource\/whitepaper\/xdr-for-ransomware-preparedness\/\" id=\"lead-magnet-btn-link\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the Whitepaper<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-36e0793f e-con-full elementor-hidden-tablet elementor-hidden-mobile e-ecs-flex e-flex e-con e-child\" data-id=\"36e0793f\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-326eefb4 elementor-widget elementor-widget-image\" data-id=\"326eefb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"500\" height=\"549\" src=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/02\/Automating-Threat-Detection-Threat-Hunting-and-Response-Cover.webp\" class=\"attachment-full size-full wp-image-36536\" alt=\"Automating Threat Detection, Threat Hunting and Response Whitepaper Cover\" srcset=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/02\/Automating-Threat-Detection-Threat-Hunting-and-Response-Cover.webp 500w, https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/02\/Automating-Threat-Detection-Threat-Hunting-and-Response-Cover-273x300.webp 273w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-2eca609 e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"2eca609\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8a1fc2e elementor-widget elementor-widget-heading\" data-id=\"8a1fc2e\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"how-it-works\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">How Ryuk Ransomware Works<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a1c3060 elementor-widget elementor-widget-text-editor\" data-id=\"a1c3060\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW265084422 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW265084422 BCX8\">The <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW265084422 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW265084422 BCX8\"> ransomware attack process follows a sophisticated multi-stage approach that maximizes both stealth and impact. Understanding this attack chain is crucial for organizations <\/span><span class=\"NormalTextRun SCXW265084422 BCX8\">seeking<\/span><span class=\"NormalTextRun SCXW265084422 BCX8\"> to defend against or respond to <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW265084422 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW265084422 BCX8\"> infections.<\/span><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0e18084 elementor-widget elementor-widget-heading\" data-id=\"0e18084\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Initial Infection and Lateral Movement<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a32b1c1 elementor-widget elementor-widget-text-editor\" data-id=\"a32b1c1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">The journey typically begins with phishing emails targeting employees within the victim organization. These aren\u2019t generic spam emails, but carefully crafted messages designed to bypass security filters and convince recipients to open malicious attachments or click dangerous links.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Once a user interacts with the malicious content, the attack chain often involves Emotet malware downloading additional <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/learn\/what-is-malware\/\">malware<\/a>, particularly trickbot malware. TrickBot serves as a powerful reconnaissance tool, performing extensive network mapping, credential harvesting, and privilege escalation activities. This trojan horse enables attackers to move laterally through the victim\u2019s infrastructure, identifying critical assets and administrative accounts.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The reconnaissance phase can last days or even weeks, with ryuk operators carefully mapping the target environment to understand backup systems, network topology, and high-value data repositories. This patient approach distinguishes Ryuk from more opportunistic ransomware families.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-10f8c57 elementor-widget elementor-widget-heading\" data-id=\"10f8c57\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Technical Capabilities<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-45edb9e elementor-widget elementor-widget-text-editor\" data-id=\"45edb9e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Ryuk demonstrates sophisticated technical capabilities that make it particularly effective at causing maximum disruption. Before beginning the encryption process, the malware terminates approximately 180 services and 40 processes to ensure nothing interferes with its operations.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The ransomware uses advanced encryption algorithms, employing AES-256 encryption for individual files and RSA-4096 encryption to protect the symmetric encryption keys. This dual-layer approach makes unauthorized decryption virtually impossible without access to the attackers\u2019 private key.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">One of Ryuk\u2019s most destructive features is its systematic destruction of backup mechanisms. The malware actively seeks out and deletes shadow copies created by Windows System Restore, eliminating one of the most common recovery options available to victims. This capability to disable windows system restore functions significantly reduces the victim\u2019s ability to recover without paying the ransom.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Ryuk can encrypt files across all mounted drives and accessible network shares, including remote administrative shares. A particularly insidious feature is its Wake-On-LAN capability, allowing compromised machines to wake up other computers on the network for encryption, ensuring maximum organizational impact even for systems not actively in use during the attack.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The malware also employs process injection techniques to execute within legitimate system processes, helping it avoid detection by traditional anti malware solutions. This stealth capability allows Ryuk to operate undetected while conducting its devastating encryption activities.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-371d9cc e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"371d9cc\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f1190b0 elementor-widget elementor-widget-heading\" data-id=\"f1190b0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Notable Ryuk Ransomware Attacks<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7e58f77 elementor-widget elementor-widget-text-editor\" data-id=\"7e58f77\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW251377195 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW251377195 BCX8\">The real-world impact of <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW251377195 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW251377195 BCX8\"> ransomware attacks has been documented across <\/span><span class=\"NormalTextRun SCXW251377195 BCX8\">numerous<\/span><span class=\"NormalTextRun SCXW251377195 BCX8\"> high-profile incidents that <\/span><span class=\"NormalTextRun SCXW251377195 BCX8\">demonstrate<\/span><span class=\"NormalTextRun SCXW251377195 BCX8\"> both the malware\u2019s technical sophistication and the operational disruption it can cause.<\/span><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9769eae elementor-widget elementor-widget-image\" data-id=\"9769eae\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"624\" height=\"372\" src=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Attacks_-A-Timeline-of-Disruption.webp\" class=\"attachment-full size-full wp-image-36761\" alt=\"Ryuk Ransomware Attacks: A Timeline of Disruption\" srcset=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Attacks_-A-Timeline-of-Disruption.webp 624w, https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Attacks_-A-Timeline-of-Disruption-300x179.webp 300w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-73fc43f elementor-widget elementor-widget-heading\" data-id=\"73fc43f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Healthcare Sector Targeting<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2337905 elementor-widget elementor-widget-text-editor\" data-id=\"2337905\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Universal Health Services became one of the most significant victims of a ryuk ransomware attack in September 2020. The incident affected over 400 medical facilities across the United States and United Kingdom, forcing healthcare workers to abandon electronic health records and revert to paper-based procedures for accessing patient records.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The timing was particularly devastating, occurring during the COVID-19 pandemic when healthcare systems were already under unprecedented strain. The attack disrupted critical operations including laboratory testing, prescription systems, and patient monitoring equipment, potentially putting lives at risk.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Sky Lakes Medical Center and Lawrence health services also fell victim to ryuk infections during this period, highlighting the ransomware\u2019s particular threat to healthcare organizations. The targeting of human services during a global health crisis demonstrated the callous nature of the threat actors behind these attacks.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-899521b elementor-widget elementor-widget-heading\" data-id=\"899521b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Media and Infrastructure Attacks<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5e985fe elementor-widget elementor-widget-text-editor\" data-id=\"5e985fe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Tribune Publishing suffered a significant ryuk attack in December 2018 that severely disrupted newspaper printing and distribution operations. Major publications including the Los Angeles Times experienced widespread delays, affecting their ability to deliver news to readers across multiple markets.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Onslow Water and Sewer Authority faced a ryuk infection in October 2018 that disrupted billing and customer service operations. This attack on critical infrastructure demonstrated Ryuk\u2019s potential to impact essential public services beyond traditional corporate targets.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e66fe31 elementor-widget elementor-widget-heading\" data-id=\"e66fe31\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Financial Impact<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-376a8dc elementor-widget elementor-widget-text-editor\" data-id=\"376a8dc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW217883429 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW217883429 BCX8\">Between 2018 and 2019, <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW217883429 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW217883429 BCX8\"> operators collected over $61 million in ransom payments across various attacks, <\/span><span class=\"NormalTextRun SCXW217883429 BCX8\">establishing<\/span><span class=\"NormalTextRun SCXW217883429 BCX8\"> the malware as one of the most financially successful ransomware strains to date. Individual ransom demands have ranged from tens of thousands to millions of dollars, often calibrated based on the victim organization\u2019s size and perceived ability to pay.<\/span><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1e1f1bb e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"1e1f1bb\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7e9746b elementor-widget elementor-widget-heading\" data-id=\"7e9746b\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"attack-vectors-distribution-methods\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Attack Vectors and Distribution Methods<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-79fd583 elementor-widget elementor-widget-text-editor\" data-id=\"79fd583\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW50400759 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW50400759 BCX8\">Understanding how <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW50400759 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW50400759 BCX8\"> infects organizations is essential for developing effective prevention strategies. The <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW50400759 BCX8\">ransomware\u2019s<\/span><span class=\"NormalTextRun SCXW50400759 BCX8\"> distribution methods have evolved over time, but certain patterns <\/span><span class=\"NormalTextRun SCXW50400759 BCX8\">remain<\/span><span class=\"NormalTextRun SCXW50400759 BCX8\"> consistent across most successful attacks.<\/span><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f4388be elementor-widget elementor-widget-heading\" data-id=\"f4388be\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Primary Distribution Chain<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-11fea53 elementor-widget elementor-widget-text-editor\" data-id=\"11fea53\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Approximately 91% of ryuk ransomware attacks begin with phishing emails targeting employees within the victim organization. These emails often contain malicious attachments, typically Microsoft Office documents with embedded macros that serve as the initial infection vector.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The attack frequently follows a three-stage process: initial Emotet infection, followed by trickbot malware deployment, and finally ryuk execution. This layered approach allows attackers to establish persistence, conduct reconnaissance, and position themselves for maximum impact before deploying the ransomware payload.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Emotet serves as the initial foothold, often delivered through convincing phishing emails that appear to come from legitimate sources. Once established, Emotet downloads additional malware, particularly TrickBot, which performs the crucial reconnaissance and <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/learn\/lateral-movement\/\">lateral movement<\/a> functions necessary for a successful ryuk attack.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e2b1a00 elementor-widget elementor-widget-heading\" data-id=\"e2b1a00\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Advanced Techniques<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9458aec elementor-widget elementor-widget-text-editor\" data-id=\"9458aec\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Sophisticated ryuk attacks may also exploit vulnerabilities such as ZeroLogon (CVE-2020-1472) in Windows servers to enhance their access and persistence within victim networks. These exploit vulnerabilities allow attackers to escalate privileges and move laterally through network environments.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The malware program communicates with <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/learn\/command-and-control-attacks\/\">command and control c2<\/a> servers to coordinate activities and receive additional instructions. These servers maintain communication with infected systems throughout the attack lifecycle, enabling real-time coordination of the encryption process across multiple systems.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Some ryuk infections have also been traced to direct exploitation of unprotected remote desktop protocol connections, highlighting the importance of securing all network access points. Attackers may also leverage legitimate but compromised credentials obtained through previous breaches or credential stuffing attacks.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d628e01 e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"d628e01\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1af21ef elementor-widget elementor-widget-heading\" data-id=\"1af21ef\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"ioc\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Indicators of Compromise<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-286295c elementor-widget elementor-widget-text-editor\" data-id=\"286295c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW180609512 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW180609512 BCX8\">Recognizing the signs of a <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW180609512 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW180609512 BCX8\"> infection early can be crucial for <\/span><span class=\"NormalTextRun SCXW180609512 BCX8\">containing<\/span><span class=\"NormalTextRun SCXW180609512 BCX8\"> damage and implementing <a href=\"https:\/\/fidelissecurity.com\/use-case\/incident-response\/\">effective incident response<\/a> procedures. Several technical and operational indicators can signal the presence of this sophisticated ransomware.<\/span><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3e860e1 elementor-widget elementor-widget-heading\" data-id=\"3e860e1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">File System Indicators<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a395ab6 elementor-widget elementor-widget-text-editor\" data-id=\"a395ab6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">The most obvious sign of a ryuk attack is the presence of ransom notes named \u201cRyukReadMe.txt\u201d or \u201cUNIQUE_ID_DO_NOT_REMOVE.txt\u201d throughout the infected system. These ransom note files appear in every directory containing encrypted files and provide instructions for contacting the attackers.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Files with .ryk or .RYK file extension indicate successful encryption by the ransomware. Victims will find that these encrypted files cannot be opened by their associated applications, and attempts to access them result in error messages or corrupted data displays.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">System administrators may notice the sudden appearance of executable files with 12-character random names in system directories. These files are often components of the Ryuk payload or associated tools used during the attack process.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6909cde elementor-widget elementor-widget-heading\" data-id=\"6909cde\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Network and Process Indicators<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d33f523 elementor-widget elementor-widget-text-editor\" data-id=\"d33f523\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Unusual network traffic to known command and control servers associated with wizard spider operations can indicate an active or pending ryuk infection. Security teams should monitor for communications to suspicious ip addresses, particularly those associated with known ransomware infrastructure.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">The detection of trickbot malware or Emotet infections should trigger <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/threat-detection-response\/automated-incident-response-in-cyber-defense\/\">immediate incident response<\/a> procedures, as these often serve as precursors to ryuk deployment. Organizations should treat any confirmed presence of these malware families as indicators of an imminent ransomware attack.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Sudden termination of security services, backup applications, and system restore functions may indicate that Ryuk is preparing to begin its encryption process. The malware systematically disables protective mechanisms before beginning file encryption to maximize its effectiveness.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-97f8e25 elementor-widget elementor-widget-heading\" data-id=\"97f8e25\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Behavioral Indicators<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0ef8b49 elementor-widget elementor-widget-text-editor\" data-id=\"0ef8b49\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">IT teams may notice widespread failures of backup systems or the inability to create new system restore points. Ryuk actively targets these recovery mechanisms as part of its strategy to force ransom payments.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Unusual administrative activity, particularly during off-hours, may indicate that attackers are conducting <a href=\"https:\/\/fidelissecurity.com\/glossary\/cyber-reconnaissance\/\">reconnaissance<\/a> or positioning themselves for the final attack phase. This activity often involves accessing sensitive data repositories and mapping network resources.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-76a659d e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"76a659d\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f3e8e11 elementor-widget elementor-widget-heading\" data-id=\"f3e8e11\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"prevention-protection-strategies\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Prevention and Protection Strategies<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-37d4016 elementor-widget elementor-widget-text-editor\" data-id=\"37d4016\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW140710748 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW140710748 BCX8\">Defending against <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW140710748 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW140710748 BCX8\"> attacks requires a comprehensive, multi-layered security approach that addresses both technical vulnerabilities and human factors. No single security measure can provide complete protection against such sophisticated threats.<\/span><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-82ccadf elementor-widget elementor-widget-video\" data-id=\"82ccadf\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;youtube_url&quot;:&quot;https:\\\/\\\/www.youtube.com\\\/watch?v=Wk5Ym5ie4Hc&quot;,&quot;video_type&quot;:&quot;youtube&quot;,&quot;controls&quot;:&quot;yes&quot;}\" data-widget_type=\"video.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-wrapper elementor-open-inline\">\n\t\t\t<div class=\"elementor-video\"><\/div>\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-73b5226 elementor-widget elementor-widget-heading\" data-id=\"73b5226\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Employee Training and Awareness<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-732b116 elementor-widget elementor-widget-text-editor\" data-id=\"732b116\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Implementing comprehensive employee training programs to <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/threat-detection-response\/phishing-detection-in-minutes\/\">recognize and avoid phishing<\/a> emails represents one of the most critical defense measures. Since the vast majority of ryuk infections begin with successful phishing attacks, educating staff about suspicious email indicators can prevent initial compromise.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Training should cover recognizing suspicious attachments, particularly Microsoft Office documents requesting macro activation, unexpected links in emails, and <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/learn\/what-is-social-engineering\/\">social engineering<\/a> tactics commonly used by cybercriminals. Regular simulated phishing exercises can help maintain awareness and identify employees who may need additional training.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Organizations should establish clear reporting procedures for suspicious emails, ensuring that employees feel comfortable reporting potential threats without fear of criticism. Quick reporting can enable security teams to respond to threats before they spread throughout the organization.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-62a380c elementor-widget elementor-widget-heading\" data-id=\"62a380c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Technical Defense Measures<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eb7bf7f elementor-widget elementor-widget-text-editor\" data-id=\"eb7bf7f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Maintaining regular, secure backups stored offline or in immutable storage systems provides the most reliable <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/network-security\/ransomware-defense-combining-ndr-edr\/\">defense against ransomware attacks<\/a>. These backups should be tested regularly to ensure they can be successfully restored and should be stored in locations that cannot be accessed by ransomware.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Deploy advanced <a href=\"https:\/\/fidelissecurity.com\/solutions\/endpoint-detection-and-response-edr-solution\/\">endpoint detection and response (EDR) solutions<\/a> with behavioral analysis capabilities that can identify ransomware-like activities before encryption begins. Deploy advanced detection solutions that combine <\/span><b><span data-contrast=\"auto\">EDR, NDR, and deception<\/span><\/b><span data-contrast=\"auto\"> for unified visibility across the attack surface.\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Platforms like <\/span><span data-contrast=\"auto\"><a style=\"font-weight: bold;\" href=\"https:\/\/fidelissecurity.com\/fidelis-elevate-extended-detection-and-response-xdr-platform\/\">Fidelis Elevate<\/a><sup style=\"font-weight: bold;\">\u00ae<\/sup> XDR<\/span><span data-contrast=\"auto\"> can detect ransomware activity in real time\u2014monitoring for lateral movement, privilege escalation, and backup sabotage\u2014before the encryption phase even starts. These tools should monitor for suspicious process behavior, unauthorized file access patterns, and attempts to delete shadow copies.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Implement robust email filtering systems to block malicious attachments and suspicious links before they reach employee inboxes. These systems should include advanced threat detection capabilities that can identify previously unknown malware variants.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e402dad elementor-widget elementor-widget-heading\" data-id=\"e402dad\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Network Security Controls<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d0e3efb elementor-widget elementor-widget-text-editor\" data-id=\"d0e3efb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Network segmentation can significantly limit the impact of a successful ryuk infection by <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/network-security\/preventing-lateral-movement-in-enterprise-network\/\">preventing lateral movement<\/a> between different parts of the organization. Critical systems should be isolated from general user networks whenever possible.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Deploy application whitelisting to prevent execution of unauthorized executable files, including ransomware payloads. This approach can stop ryuk from executing even if other security measures fail to prevent the initial infection.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Implement robust access controls with multi-factor authentication for all administrative and user accounts. Limiting user privileges to only what is necessary for their job functions can reduce the potential impact of compromised credentials.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4eedb6f elementor-widget elementor-widget-heading\" data-id=\"4eedb6f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">System Maintenance<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4de22ba elementor-widget elementor-widget-text-editor\" data-id=\"4de22ba\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Keep all systems and software updated with the latest security patches to prevent exploitation of known vulnerabilities. Many successful ransomware attacks exploit vulnerabilities that have available patches but haven\u2019t been applied to victim systems.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Regularly audit and secure remote desktop protocol connections, ensuring they are protected by strong authentication and not directly accessible from the internet. Many ryuk infections have leveraged unsecured RDP connections as initial access vectors.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Monitor for indicators of compromise associated with precursor malware like TrickBot and Emotet. Early detection of these infections can enable organizations to prevent the subsequent deployment of Ryuk.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-864c089 e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"864c089\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ed55f34 elementor-widget elementor-widget-heading\" data-id=\"ed55f34\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"incident-response-recovery\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Incident Response and Recovery<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bad9fba elementor-widget elementor-widget-text-editor\" data-id=\"bad9fba\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span class=\"TextRun SCXW220358937 BCX8\" lang=\"EN-US\" xml:lang=\"EN-US\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW220358937 BCX8\">When facing a confirmed or suspected <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW220358937 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW220358937 BCX8\"> infection, organizations must act quickly and decisively to minimize damage and begin recovery operations. The first hours of an incident are critical for <\/span><span class=\"NormalTextRun SCXW220358937 BCX8\">containing<\/span><span class=\"NormalTextRun SCXW220358937 BCX8\"> the threat and preserving evidence for investigation.<\/span><\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ef63537 elementor-widget elementor-widget-heading\" data-id=\"ef63537\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Immediate Response Actions<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3bec60d elementor-widget elementor-widget-text-editor\" data-id=\"3bec60d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Immediately isolate affected systems to prevent further spread across the network. This may involve disconnecting network cables, disabling wireless connections, or implementing emergency network segmentation procedures. Speed is essential, as Ryuk can encrypt network drives and resources rapidly once activated.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Contact law enforcement agencies, particularly the FBI\u2019s Internet Crime Complaint Center, to report the ransomware attack. Law enforcement can provide valuable assistance and may have intelligence about the specific threat actors or ongoing investigations that could aid recovery efforts.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Engage cybersecurity professionals experienced in <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/xdr-security\/ransomware-response-plan-fidelis-elevate\/\">ransomware incident response<\/a> as quickly as possible. These specialists can help assess the scope of the infection, identify the attack vector, and develop an appropriate response strategy.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-3343290c e-con-full e-ecs-flex e-flex e-con e-child\" data-id=\"3343290c\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;,&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t<div class=\"elementor-element elementor-element-3d90027e e-con-full e-ecs-flex e-flex e-con e-child\" data-id=\"3d90027e\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8ed4a elementor-widget elementor-widget-heading\" data-id=\"8ed4a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Critical Incident Response: Key Steps for the First 72 Hours<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-31351471 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"31351471\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"30\" height=\"32\" viewBox=\"0 0 30 32\" fill=\"none\"><path d=\"M28.4233 16.5056C28.3177 16.1761 28.3177 15.8209 28.4233 15.4913L29.4568 12.3171C29.6744 11.6419 29.4344 10.8996 28.8585 10.4836L26.1578 8.51886C25.8794 8.31727 25.6683 8.02927 25.5627 7.69972L24.5291 4.52227C24.3115 3.84711 23.6811 3.38952 22.9676 3.38952H19.6302C19.2846 3.38952 18.9454 3.28074 18.6638 3.07594L15.9632 1.11445C15.3904 0.69525 14.6096 0.69525 14.0369 1.11445L11.333 3.07594C11.0546 3.28074 10.7154 3.38952 10.3699 3.38952H7.02926C6.31887 3.38952 5.68851 3.84711 5.4709 4.52548L4.43736 7.69972C4.33174 8.02927 4.12058 8.31727 3.839 8.52206L1.14152 10.4836C0.565577 10.8996 0.32559 11.6419 0.543196 12.3171L1.57673 15.4913C1.68232 15.8209 1.68232 16.1761 1.57673 16.5056L0.543196 19.6831C0.32559 20.3582 0.565577 21.1006 1.14152 21.5166L3.8422 23.4781C4.12058 23.6829 4.32858 23.9708 4.43736 24.3004L5.4677 27.4746C5.68851 28.153 6.31887 28.6106 7.02926 28.6106H10.3699C10.7154 28.6106 11.0514 28.7194 11.333 28.921L14.0369 30.8857C14.6096 31.3048 15.3904 31.3048 15.9632 30.8857L18.667 28.921C18.9454 28.7194 19.2846 28.6106 19.6302 28.6106H22.9708C23.6811 28.6106 24.3115 28.153 24.5291 27.4746L25.5627 24.3004C25.6683 23.9708 25.8794 23.6829 26.1578 23.4781L28.8585 21.5166C29.4344 21.1006 29.6744 20.3582 29.4568 19.6831L28.4233 16.5056ZM21.7132 12.8418C21.7132 13.2642 21.5468 13.661 21.2493 13.9586L14.9392 20.2654C14.6544 20.5502 14.2512 20.7134 13.8289 20.7134C13.4065 20.7134 13.0001 20.5502 12.7153 20.2654L8.74432 16.3008C8.13318 15.6897 8.13318 14.6913 8.74112 14.0738C9.33953 13.4754 10.3795 13.4754 10.9746 14.0706L13.8257 16.9216L19.019 11.7283C19.6173 11.1395 20.6605 11.1395 21.2493 11.7283C21.5468 12.0259 21.7132 12.4227 21.7132 12.8418Z\" fill=\"url(#paint0_linear_227_654)\"><\/path><defs><linearGradient id=\"paint0_linear_227_654\" x1=\"15\" y1=\"0.800049\" x2=\"15\" y2=\"31.2\" gradientUnits=\"userSpaceOnUse\"><stop stop-color=\"#E55E06\"><\/stop><stop offset=\"1\" stop-color=\"#C00000\"><\/stop><\/linearGradient><\/defs><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">What data has been potentially  exposed?<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"30\" height=\"32\" viewBox=\"0 0 30 32\" fill=\"none\"><path d=\"M28.4233 16.5056C28.3177 16.1761 28.3177 15.8209 28.4233 15.4913L29.4568 12.3171C29.6744 11.6419 29.4344 10.8996 28.8585 10.4836L26.1578 8.51886C25.8794 8.31727 25.6683 8.02927 25.5627 7.69972L24.5291 4.52227C24.3115 3.84711 23.6811 3.38952 22.9676 3.38952H19.6302C19.2846 3.38952 18.9454 3.28074 18.6638 3.07594L15.9632 1.11445C15.3904 0.69525 14.6096 0.69525 14.0369 1.11445L11.333 3.07594C11.0546 3.28074 10.7154 3.38952 10.3699 3.38952H7.02926C6.31887 3.38952 5.68851 3.84711 5.4709 4.52548L4.43736 7.69972C4.33174 8.02927 4.12058 8.31727 3.839 8.52206L1.14152 10.4836C0.565577 10.8996 0.32559 11.6419 0.543196 12.3171L1.57673 15.4913C1.68232 15.8209 1.68232 16.1761 1.57673 16.5056L0.543196 19.6831C0.32559 20.3582 0.565577 21.1006 1.14152 21.5166L3.8422 23.4781C4.12058 23.6829 4.32858 23.9708 4.43736 24.3004L5.4677 27.4746C5.68851 28.153 6.31887 28.6106 7.02926 28.6106H10.3699C10.7154 28.6106 11.0514 28.7194 11.333 28.921L14.0369 30.8857C14.6096 31.3048 15.3904 31.3048 15.9632 30.8857L18.667 28.921C18.9454 28.7194 19.2846 28.6106 19.6302 28.6106H22.9708C23.6811 28.6106 24.3115 28.153 24.5291 27.4746L25.5627 24.3004C25.6683 23.9708 25.8794 23.6829 26.1578 23.4781L28.8585 21.5166C29.4344 21.1006 29.6744 20.3582 29.4568 19.6831L28.4233 16.5056ZM21.7132 12.8418C21.7132 13.2642 21.5468 13.661 21.2493 13.9586L14.9392 20.2654C14.6544 20.5502 14.2512 20.7134 13.8289 20.7134C13.4065 20.7134 13.0001 20.5502 12.7153 20.2654L8.74432 16.3008C8.13318 15.6897 8.13318 14.6913 8.74112 14.0738C9.33953 13.4754 10.3795 13.4754 10.9746 14.0706L13.8257 16.9216L19.019 11.7283C19.6173 11.1395 20.6605 11.1395 21.2493 11.7283C21.5468 12.0259 21.7132 12.4227 21.7132 12.8418Z\" fill=\"url(#paint0_linear_227_654)\"><\/path><defs><linearGradient id=\"paint0_linear_227_654\" x1=\"15\" y1=\"0.800049\" x2=\"15\" y2=\"31.2\" gradientUnits=\"userSpaceOnUse\"><stop stop-color=\"#E55E06\"><\/stop><stop offset=\"1\" stop-color=\"#C00000\"><\/stop><\/linearGradient><\/defs><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">Incursion detection and Persistence detection<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"30\" height=\"32\" viewBox=\"0 0 30 32\" fill=\"none\"><path d=\"M28.4233 16.5056C28.3177 16.1761 28.3177 15.8209 28.4233 15.4913L29.4568 12.3171C29.6744 11.6419 29.4344 10.8996 28.8585 10.4836L26.1578 8.51886C25.8794 8.31727 25.6683 8.02927 25.5627 7.69972L24.5291 4.52227C24.3115 3.84711 23.6811 3.38952 22.9676 3.38952H19.6302C19.2846 3.38952 18.9454 3.28074 18.6638 3.07594L15.9632 1.11445C15.3904 0.69525 14.6096 0.69525 14.0369 1.11445L11.333 3.07594C11.0546 3.28074 10.7154 3.38952 10.3699 3.38952H7.02926C6.31887 3.38952 5.68851 3.84711 5.4709 4.52548L4.43736 7.69972C4.33174 8.02927 4.12058 8.31727 3.839 8.52206L1.14152 10.4836C0.565577 10.8996 0.32559 11.6419 0.543196 12.3171L1.57673 15.4913C1.68232 15.8209 1.68232 16.1761 1.57673 16.5056L0.543196 19.6831C0.32559 20.3582 0.565577 21.1006 1.14152 21.5166L3.8422 23.4781C4.12058 23.6829 4.32858 23.9708 4.43736 24.3004L5.4677 27.4746C5.68851 28.153 6.31887 28.6106 7.02926 28.6106H10.3699C10.7154 28.6106 11.0514 28.7194 11.333 28.921L14.0369 30.8857C14.6096 31.3048 15.3904 31.3048 15.9632 30.8857L18.667 28.921C18.9454 28.7194 19.2846 28.6106 19.6302 28.6106H22.9708C23.6811 28.6106 24.3115 28.153 24.5291 27.4746L25.5627 24.3004C25.6683 23.9708 25.8794 23.6829 26.1578 23.4781L28.8585 21.5166C29.4344 21.1006 29.6744 20.3582 29.4568 19.6831L28.4233 16.5056ZM21.7132 12.8418C21.7132 13.2642 21.5468 13.661 21.2493 13.9586L14.9392 20.2654C14.6544 20.5502 14.2512 20.7134 13.8289 20.7134C13.4065 20.7134 13.0001 20.5502 12.7153 20.2654L8.74432 16.3008C8.13318 15.6897 8.13318 14.6913 8.74112 14.0738C9.33953 13.4754 10.3795 13.4754 10.9746 14.0706L13.8257 16.9216L19.019 11.7283C19.6173 11.1395 20.6605 11.1395 21.2493 11.7283C21.5468 12.0259 21.7132 12.4227 21.7132 12.8418Z\" fill=\"url(#paint0_linear_227_654)\"><\/path><defs><linearGradient id=\"paint0_linear_227_654\" x1=\"15\" y1=\"0.800049\" x2=\"15\" y2=\"31.2\" gradientUnits=\"userSpaceOnUse\"><stop stop-color=\"#E55E06\"><\/stop><stop offset=\"1\" stop-color=\"#C00000\"><\/stop><\/linearGradient><\/defs><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">How should I respond?<\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-52c5842f elementor-widget elementor-widget-button\" data-id=\"52c5842f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/fidelissecurity.com\/resource\/whitepaper\/first-72-hours-incident-response-playbook\/\" id=\"lead-magnet-btn-link\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the Whitepaper<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-58cdc0da e-con-full elementor-hidden-tablet elementor-hidden-mobile e-ecs-flex e-flex e-con e-child\" data-id=\"58cdc0da\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-51eaceb7 elementor-widget elementor-widget-image\" data-id=\"51eaceb7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"677\" height=\"743\" src=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2024\/06\/First-72-Hours-of-Security-Incident.webp\" class=\"attachment-full size-full wp-image-35035\" alt=\"incident response within 72 hours guide cover\" srcset=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2024\/06\/First-72-Hours-of-Security-Incident.webp 677w, https:\/\/fidelissecurity.com\/wp-content\/uploads\/2024\/06\/First-72-Hours-of-Security-Incident-273x300.webp 273w\" sizes=\"(max-width: 677px) 100vw, 677px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e527be6 elementor-widget elementor-widget-heading\" data-id=\"e527be6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Assessment and Documentation<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-13657b9 elementor-widget elementor-widget-text-editor\" data-id=\"13657b9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Conduct a thorough assessment to determine which systems and data have been affected by the ryuk infection. This assessment should include all network-connected systems, backup repositories, and any cloud-based resources that may have been compromised.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Document all actions taken during the incident response process for potential legal proceedings and insurance claims. This documentation should include timestamps, personnel involved, and detailed descriptions of all response activities.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Preserve forensic evidence that may be useful for law enforcement investigations or internal analysis. This evidence can help identify how the attack occurred and prevent similar incidents in the future.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6fddcb3 elementor-widget elementor-widget-heading\" data-id=\"6fddcb3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Recovery Considerations<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-894fb3e elementor-widget elementor-widget-text-editor\" data-id=\"894fb3e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Security experts and law enforcement agencies strongly advise against paying ransom demands. Payment does not guarantee that encrypted files will be recovered, and it directly funds criminal operations that enable future attacks against other organizations.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Focus recovery efforts on restoring data from clean, uncompromised backups created before the ryuk infection occurred. This process may take considerable time but represents the most reliable path to full data recovery.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Before restoring any systems, ensure that the threat has been completely eliminated from the network environment. Premature restoration can result in re-infection and the loss of recovered data.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-047fd9c elementor-widget elementor-widget-heading\" data-id=\"047fd9c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Post-Incident Activities<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-144dd53 elementor-widget elementor-widget-text-editor\" data-id=\"144dd53\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span data-contrast=\"auto\">Conduct a comprehensive post-incident analysis to identify security weaknesses that enabled the attack and develop remediation plans to address these vulnerabilities. This analysis should examine both technical controls and operational procedures.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Update <a href=\"https:\/\/fidelissecurity.com\/cybersecurity-101\/learn\/what-is-an-incident-response-plan\/\">incident response plans<\/a> based on lessons learned during the ryuk attack. These updates should address any gaps or inefficiencies identified during the response process.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/p><p><span data-contrast=\"auto\">Consider engaging third-party security assessors to conduct independent evaluations of security controls and help identify additional areas for improvement.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-664ce797 e-ecs-flex e-flex e-con-boxed e-con e-parent\" data-id=\"664ce797\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;ecs_container_type&quot;:&quot;flex&quot;,&quot;_ha_eqh_enable&quot;:false}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-37fc7bf0 elementor-widget elementor-widget-heading\" data-id=\"37fc7bf0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Frequently Ask Questions<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-77d0067b elementor-widget elementor-widget-eael-adv-accordion\" data-id=\"77d0067b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"eael-adv-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t            <div class=\"eael-adv-accordion\" id=\"eael-adv-accordion-77d0067b\" data-scroll-on-click=\"no\" data-scroll-speed=\"300\" data-accordion-id=\"77d0067b\" data-accordion-type=\"accordion\" data-toogle-speed=\"300\">\n            <div class=\"eael-accordion-list\">\n\t\t\t\t\t<div id=\"what-makes-ryuk-ransomware-different\" class=\"elementor-tab-title eael-accordion-header active-default\" tabindex=\"0\" data-tab=\"1\" aria-controls=\"elementor-tab-content-2011\"><h3 class=\"eael-accordion-tab-title\">What makes Ryuk different from other ransomware?<\/h3><i aria-hidden=\"true\" class=\"fa-toggle fas fa-angle-right\"><\/i><\/div><div id=\"elementor-tab-content-2011\" class=\"eael-accordion-content clearfix active-default\" data-tab=\"1\" aria-labelledby=\"what-makes-ryuk-ransomware-different\"><p><span class=\"TextRun SCXW106073787 BCX8\"><span class=\"NormalTextRun SCXW106073787 BCX8\">Ryuk specifically targets high-value organizations through manual reconnaissance and can encrypt network resources, not just local files. It also <\/span><span class=\"NormalTextRun SCXW106073787 BCX8\">deletes<\/span><span class=\"NormalTextRun SCXW106073787 BCX8\"> shadow copies to prevent easy recovery and <\/span><span class=\"NormalTextRun SCXW106073787 BCX8\">operates<\/span><span class=\"NormalTextRun SCXW106073787 BCX8\"> with a level of sophistication that sets it apart from most ransomware families. The targeted attacks focus on large organizations rather than broad, automated campaigns.<\/span><\/span><span class=\"EOP SCXW106073787 BCX8\">\u00a0<\/span><\/p><\/div>\n\t\t\t\t\t<\/div><div class=\"eael-accordion-list\">\n\t\t\t\t\t<div id=\"can-you-decrypt-ryuk-ransomware\" class=\"elementor-tab-title eael-accordion-header\" tabindex=\"0\" data-tab=\"2\" aria-controls=\"elementor-tab-content-2012\"><h3 class=\"eael-accordion-tab-title\">Can Ryuk be decrypted without paying the ransom?<\/h3><i aria-hidden=\"true\" class=\"fa-toggle fas fa-angle-right\"><\/i><\/div><div id=\"elementor-tab-content-2012\" class=\"eael-accordion-content clearfix\" data-tab=\"2\" aria-labelledby=\"can-you-decrypt-ryuk-ransomware\"><p><span class=\"TextRun SCXW66566468 BCX8\"><span class=\"NormalTextRun SCXW66566468 BCX8\">Currently, there are no free decryption tools available for Ryuk due to its use of strong encryption algorithms. Recovery typically requires <\/span><span class=\"NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW66566468 BCX8\">restoring from<\/span><span class=\"NormalTextRun SCXW66566468 BCX8\"> clean backups created before the infection occurred. The combination of AES-256 and RSA-4096 encryption makes unauthorized decryption <\/span><span class=\"NormalTextRun SCXW66566468 BCX8\">virtually impossible<\/span><span class=\"NormalTextRun SCXW66566468 BCX8\">.<\/span><\/span><\/p><\/div>\n\t\t\t\t\t<\/div><div class=\"eael-accordion-list\">\n\t\t\t\t\t<div id=\"how-long-ryuk-attack-takes\" class=\"elementor-tab-title eael-accordion-header\" tabindex=\"0\" data-tab=\"3\" aria-controls=\"elementor-tab-content-2013\"><h3 class=\"eael-accordion-tab-title\">How long does a typical Ryuk attack take? <\/h3><i aria-hidden=\"true\" class=\"fa-toggle fas fa-angle-right\"><\/i><\/div><div id=\"elementor-tab-content-2013\" class=\"eael-accordion-content clearfix\" data-tab=\"3\" aria-labelledby=\"how-long-ryuk-attack-takes\"><p><span class=\"TextRun SCXW162324821 BCX8\"><span class=\"NormalTextRun SCXW162324821 BCX8\">From <\/span><span class=\"NormalTextRun SCXW162324821 BCX8\">initial<\/span><span class=\"NormalTextRun SCXW162324821 BCX8\"> infection to full encryption can take anywhere from hours to weeks, depending on network size and the attackers\u2019 reconnaissance activities. The <\/span><span class=\"NormalTextRun SpellingErrorV2Themed SCXW162324821 BCX8\">ryuk<\/span><span class=\"NormalTextRun SCXW162324821 BCX8\"> operators often spend considerable time mapping the target environment before deploying the ransomware payload to maximize impact.<\/span><\/span><\/p><\/div>\n\t\t\t\t\t<\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.<\/p>\n","protected":false},"author":19,"featured_media":37134,"comment_status":"closed","ping_status":"closed","template":"","categories":[1129,239,247,13,734],"tags":[630,1036,733],"class_list":["post-36757","cybersecurity-101","type-cybersecurity-101","status-publish","has-post-thumbnail","hentry","category-cyberattacks","category-learn","category-network-security","category-threat-intelligence","category-threats-and-vulnerabilities","tag-example-of-ransomware-attacks","tag-ndr-for-ransomware-attack","tag-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What is Ryuk Ransomware? | Fidelis Security<\/title>\n<meta name=\"description\" content=\"Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is Ryuk Ransomware? | Fidelis Security\" \/>\n<meta property=\"og:description\" content=\"Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/\" \/>\n<meta property=\"og:site_name\" content=\"Fidelis Security\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/fideliscyber\/\" \/>\n<meta property=\"article:modified_time\" content=\"2025-08-07T17:34:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-open-graph.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"What is Ryuk Ransomware? | Fidelis Security\" \/>\n<meta name=\"twitter:description\" content=\"Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-X-Card.webp\" \/>\n<meta name=\"twitter:site\" content=\"@FidelisCyber\" \/>\n<meta name=\"twitter:label1\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data1\" content=\"15 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/\"},\"author\":{\"name\":\"Sarika Sharma\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#\\\/schema\\\/person\\\/7b3d0a7ba4d78e785849b109d94f45d3\"},\"headline\":\"What is Ryuk: Complete Guide to the Notorious Ransomware\",\"datePublished\":\"2025-06-30T12:15:59+00:00\",\"dateModified\":\"2025-08-07T17:34:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/\"},\"wordCount\":3059,\"publisher\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/Ryuk-Ransomware-Featured.webp\",\"keywords\":[\"example of ransomware attacks\",\"NDR for Ransomware Attack\",\"Ransomware\"],\"articleSection\":[\"Cyber Attacks\",\"Education Center\",\"Network Security\",\"Threat Intelligence\",\"Threats and Vulnerabilities\"],\"inLanguage\":\"es\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/\",\"url\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/\",\"name\":\"What is Ryuk Ransomware? | Fidelis Security\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/Ryuk-Ransomware-Featured.webp\",\"datePublished\":\"2025-06-30T12:15:59+00:00\",\"dateModified\":\"2025-08-07T17:34:56+00:00\",\"description\":\"Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/Ryuk-Ransomware-Featured.webp\",\"contentUrl\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/Ryuk-Ransomware-Featured.webp\",\"width\":800,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/cyberattacks\\\/ryuk-ransomware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity 101\",\"item\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/cybersecurity-101\\\/%category%\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Cyber Attacks\",\"item\":\"https:\\\/\\\/fidelissecurity.com\\\/threatgeek\\\/category\\\/cyberattacks\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"What is Ryuk: Complete Guide to the Notorious Ransomware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#website\",\"url\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/\",\"name\":\"Fidelis Security\",\"description\":\"Unified Threat Detection and Response Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#organization\"},\"alternateName\":\"Fidelis\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#organization\",\"name\":\"Fidelis Security\",\"alternateName\":\"Fidelis\",\"url\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/Fidelis-Security-Logo-SVG.svg\",\"contentUrl\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/Fidelis-Security-Logo-SVG.svg\",\"width\":500,\"height\":500,\"caption\":\"Fidelis Security\"},\"image\":{\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/fideliscyber\\\/\",\"https:\\\/\\\/x.com\\\/FidelisCyber\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/fideliscybersecurity\",\"https:\\\/\\\/www.youtube.com\\\/c\\\/FidelisCybersecurity\",\"https:\\\/\\\/www.gartner.com\\\/reviews\\\/market\\\/network-detection-and-response\\\/vendor\\\/fidelis-security\",\"https:\\\/\\\/www.g2.com\\\/sellers\\\/fidelis-cybersecurity#profiles\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/#\\\/schema\\\/person\\\/7b3d0a7ba4d78e785849b109d94f45d3\",\"name\":\"Sarika Sharma\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Sarika-Sharma-150x150.webp\",\"url\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Sarika-Sharma-150x150.webp\",\"contentUrl\":\"https:\\\/\\\/fidelissecurity.com\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Sarika-Sharma-150x150.webp\",\"caption\":\"Sarika Sharma\"},\"description\":\"Sarika, a cybersecurity enthusiast, contributes insightful articles to Fidelis Security, guiding readers through the complexities of digital security with clarity and passion. Beyond her writing, she actively engages in the cybersecurity community, staying informed about emerging trends and technologies to empower individuals and organizations in safeguarding their digital assets.\",\"sameAs\":[\"https:\\\/\\\/fidelissecurity.com\\\/\"],\"url\":\"https:\\\/\\\/fidelissecurity.com\\\/es\\\/threatgeek\\\/author\\\/sarika-sharma\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is Ryuk Ransomware? | Fidelis Security","description":"Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/","og_locale":"es_ES","og_type":"article","og_title":"What is Ryuk Ransomware? | Fidelis Security","og_description":"Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.","og_url":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/","og_site_name":"Fidelis Security","article_publisher":"https:\/\/www.facebook.com\/fideliscyber\/","article_modified_time":"2025-08-07T17:34:56+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-open-graph.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_title":"What is Ryuk Ransomware? | Fidelis Security","twitter_description":"Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.","twitter_image":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-X-Card.webp","twitter_site":"@FidelisCyber","twitter_misc":{"Tiempo de lectura":"15 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/#article","isPartOf":{"@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/"},"author":{"name":"Sarika Sharma","@id":"https:\/\/fidelissecurity.com\/es\/#\/schema\/person\/7b3d0a7ba4d78e785849b109d94f45d3"},"headline":"What is Ryuk: Complete Guide to the Notorious Ransomware","datePublished":"2025-06-30T12:15:59+00:00","dateModified":"2025-08-07T17:34:56+00:00","mainEntityOfPage":{"@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/"},"wordCount":3059,"publisher":{"@id":"https:\/\/fidelissecurity.com\/es\/#organization"},"image":{"@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Featured.webp","keywords":["example of ransomware attacks","NDR for Ransomware Attack","Ransomware"],"articleSection":["Cyber Attacks","Education Center","Network Security","Threat Intelligence","Threats and Vulnerabilities"],"inLanguage":"es"},{"@type":"WebPage","@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/","url":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/","name":"What is Ryuk Ransomware? | Fidelis Security","isPartOf":{"@id":"https:\/\/fidelissecurity.com\/es\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/#primaryimage"},"image":{"@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/#primaryimage"},"thumbnailUrl":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Featured.webp","datePublished":"2025-06-30T12:15:59+00:00","dateModified":"2025-08-07T17:34:56+00:00","description":"Discover essential insights on Ryuk ransomware and learn effective prevention strategies to safeguard your data. Read the article for practical tips.","breadcrumb":{"@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/#primaryimage","url":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Featured.webp","contentUrl":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2025\/06\/Ryuk-Ransomware-Featured.webp","width":800,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/cyberattacks\/ryuk-ransomware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fidelissecurity.com\/es\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity 101","item":"https:\/\/fidelissecurity.com\/es\/cybersecurity-101\/%category%\/"},{"@type":"ListItem","position":3,"name":"Cyber Attacks","item":"https:\/\/fidelissecurity.com\/threatgeek\/category\/cyberattacks\/"},{"@type":"ListItem","position":4,"name":"What is Ryuk: Complete Guide to the Notorious Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/fidelissecurity.com\/es\/#website","url":"https:\/\/fidelissecurity.com\/es\/","name":"Fidelis Security","description":"Unified Threat Detection and Response Platform","publisher":{"@id":"https:\/\/fidelissecurity.com\/es\/#organization"},"alternateName":"Fidelis","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fidelissecurity.com\/es\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/fidelissecurity.com\/es\/#organization","name":"Fidelis Security","alternateName":"Fidelis","url":"https:\/\/fidelissecurity.com\/es\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/fidelissecurity.com\/es\/#\/schema\/logo\/image\/","url":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2024\/08\/Fidelis-Security-Logo-SVG.svg","contentUrl":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2024\/08\/Fidelis-Security-Logo-SVG.svg","width":500,"height":500,"caption":"Fidelis Security"},"image":{"@id":"https:\/\/fidelissecurity.com\/es\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/fideliscyber\/","https:\/\/x.com\/FidelisCyber","https:\/\/www.linkedin.com\/company\/fideliscybersecurity","https:\/\/www.youtube.com\/c\/FidelisCybersecurity","https:\/\/www.gartner.com\/reviews\/market\/network-detection-and-response\/vendor\/fidelis-security","https:\/\/www.g2.com\/sellers\/fidelis-cybersecurity#profiles"]},{"@type":"Person","@id":"https:\/\/fidelissecurity.com\/es\/#\/schema\/person\/7b3d0a7ba4d78e785849b109d94f45d3","name":"Sarika Sharma","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2024\/05\/Sarika-Sharma-150x150.webp","url":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2024\/05\/Sarika-Sharma-150x150.webp","contentUrl":"https:\/\/fidelissecurity.com\/wp-content\/uploads\/2024\/05\/Sarika-Sharma-150x150.webp","caption":"Sarika Sharma"},"description":"Sarika, a cybersecurity enthusiast, contributes insightful articles to Fidelis Security, guiding readers through the complexities of digital security with clarity and passion. Beyond her writing, she actively engages in the cybersecurity community, staying informed about emerging trends and technologies to empower individuals and organizations in safeguarding their digital assets.","sameAs":["https:\/\/fidelissecurity.com\/"],"url":"https:\/\/fidelissecurity.com\/es\/threatgeek\/author\/sarika-sharma\/"}]}},"_links":{"self":[{"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/cybersecurity-101\/36757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/cybersecurity-101"}],"about":[{"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/types\/cybersecurity-101"}],"author":[{"embeddable":true,"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/comments?post=36757"}],"version-history":[{"count":0,"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/cybersecurity-101\/36757\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/media\/37134"}],"wp:attachment":[{"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/media?parent=36757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/categories?post=36757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fidelissecurity.com\/es\/wp-json\/wp\/v2\/tags?post=36757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}