www.picussecurity.com Ryuk Ransomware: Ongoing Threat to Large Organizations
Article Content
- •Ryuk ransomware targets large organizations, often in critical sectors like healthcare.
- •The malware employs advanced encryption techniques and disables backup services to maximize impact.
- •Ransom demands can reach millions, with a history of significant financial losses for victims.
Ryuk ransomware, attributed to the Russian group Wizard Spider, continues to target large organizations, particularly in sectors like healthcare and government. The malware is delivered through phishing attacks and often relies on other malware like Emotet or TrickBot for initial access. Once inside a network, Ryuk can disable critical services, encrypt files using AES-256 and RSA-4096 encryption, and demand ransoms that can reach millions of dollars. Notable past attacks include disruptions to Tribune Publishing and Jackson County, Georgia. Security professionals are urged to enhance their defenses against this persistent threat, which has resulted in significant financial losses for victims. The ransomware's ability to perform remote encryption and disable backup systems complicates recovery efforts. As of now, Ryuk remains a significant threat, with ongoing attacks reported.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ryuk, Unc1878 and BazarBackdoor in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PAYLOAD Ransomware Exploits Active Directory GPO for Disruption In April 2026, Kaspersky's Global Emergency Response Team (GERT) responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control via a compromised FortiGate SSL VPN account and created a malicious Group Policy Object (GPO) named PAYLOAD. This GPO…
Education Sector Faces Surge in Cyberattacks Amid Open Network Vulnerabilities SonicWall's 2026 Education Protect Brief reveals that educational institutions are experiencing the highest per-device cyberattack intensity of any tracked sector, with 81,879 intrusion prevention system (IPS) hits per device in the first half of 2026. The report highlights that SIPVicious VoIP exploitation accounted…