Skip to content
Ryuk Ransomware: Ongoing Threat to Large Organizations

Ryuk Ransomware: Ongoing Threat to Large Organizations

First seen 24 Sep 2026, 00:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 02:27 UTC
  • Ryuk ransomware targets large organizations, often in critical sectors like healthcare.
  • The malware employs advanced encryption techniques and disables backup services to maximize impact.
  • Ransom demands can reach millions, with a history of significant financial losses for victims.

Ryuk ransomware, attributed to the Russian group Wizard Spider, continues to target large organizations, particularly in sectors like healthcare and government. The malware is delivered through phishing attacks and often relies on other malware like Emotet or TrickBot for initial access. Once inside a network, Ryuk can disable critical services, encrypt files using AES-256 and RSA-4096 encryption, and demand ransoms that can reach millions of dollars. Notable past attacks include disruptions to Tribune Publishing and Jackson County, Georgia. Security professionals are urged to enhance their defenses against this persistent threat, which has resulted in significant financial losses for victims. The ransomware's ability to perform remote encryption and disable backup systems complicates recovery efforts. As of now, Ryuk remains a significant threat, with ongoing attacks reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2018-12-01
First major attack reported
Tribune Publishing was infected by Ryuk, causing major disruptions in newspaper printing.
Trend Micro
2019-01-01
High ransom demands noted
Ryuk had the highest ransom demand at USD $12.5 million, contributing to a total of USD $150 million by the end of 2020.
Trend Micro
2019-01-01
Jackson County attack
Jackson County, Georgia, suffered an attack that led to a $400,000 ransom payment to restore IT systems.
Huntress
2026-09-24
Current threat analysis
Recent analysis highlights ongoing Ryuk ransomware attacks, emphasizing its sophisticated methods and high impact.
Picus Security

More articles in this cluster (3)

Following this threat?

Track Ryuk, Unc1878 and BazarBackdoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed