Ryuk Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
14
occurrences
First Seen
October 31, 2025
Last Seen
July 16, 2026

Ryuk is a ransomware_group tracked across 14 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity July 16, 2026.

Related Threat Clusters

  • EU Sanctions Vitaly Kovalev, Ransomware Leader of Trickbot Group

    On July 14, 2026, the European Union, in coordination with the U.S. and U.K., sanctioned Vitaly Nikolayevich Kovalev, known as 'Stern,' a key figure in the Trickbot ransomware syndicate. Kovalev is linked to over $300…

    4 articles · Updated July 15, 2026
  • US Indicts Russian Nationals for $62M Cybercrime Scheme Targeting Critical Infrastructure

    On July 14, 2026, the US Justice Department unsealed an indictment against three Russian nationals—Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova—accused of operating bulletproof hosting services that…

    29 articles · Updated July 14, 2026
  • Exploitation of Remote Services in Cyber Attacks

    Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…

    2 articles · Updated June 3, 2026
  • Ukrainian National Pleads Guilty in Conti Ransomware Case

    Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, pleaded guilty to conspiracy to commit wire fraud related to the Conti ransomware operation. This group was responsible for over 1,000 attacks…

    17 articles · Updated June 12, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1553 articles · Updated February 12, 2026
  • US Government Agency Paid $1M to Data Extortion Group Kairos

    A U.S. government entity reportedly paid $1 million to the Kairos extortion group to prevent the public release of sensitive data. The payment was revealed in a Ransom-ISAC case study, which utilized a leaked…

    9 articles · Updated July 4, 2026
  • FBI Seizes RAMP Cybercrime Forum Used by Ransomware Gangs

    The FBI has seized the RAMP cybercrime forum, a key platform for ransomware operations and other digital crimes. Both the forum's dark web and clearnet domains now display a seizure notice attributed to the FBI,…

    16 articles · Updated January 28, 2026
  • Black Basta Ransomware Integrates BYOVD Defense Evasion Technique

    The Black Basta ransomware gang has incorporated a bring-your-own-vulnerable-driver (BYOVD) defense evasion component within its ransomware payload. This technique, which typically involves separate tools to disable…

    9 articles · Updated February 9, 2026
  • Global Signing of the Hanoi Convention Against Cybercrime

    On October 25, 2025, the United Nations Convention against Cybercrime was opened for signature in Hanoi, Vietnam, with 72 countries signing the treaty. This treaty aims to combat cybercrime and enhance international…

    4 articles · Updated May 21, 2026
  • Ukrainian National Extradited for Conti Ransomware Charges Facing 25 Years in Prison

    Oleksii Oleksiyovych Lytvynenko, a 43-year-old Ukrainian national, has been extradited from Ireland to the United States on charges related to the Conti ransomware group. He allegedly controlled stolen data and sent…

    2 articles · Updated October 31, 2025

Recent Intelligence Reports

  • EU Sanctions 'Stern,' Trickbot Ransomware Leader Tied to $300M — Blockchain.News · July 16, 2026
  • US indicts three Russians accused of powering global cybercrime — Bitdefender · July 15, 2026
  • The EU sanctions "the most active ransomware operator in history" Stern, involved in over ... — Chaincatcher · July 15, 2026
  • “Stern” Ransomware Operator Sanctioned by EU — Chainalysis · July 14, 2026
  • Fbi Warns Of Luna Moth Extortion Attacks Targeting Law Firms — www.bleepingcomputer.com · July 5, 2026
  • T1021 — attack.mitre.org · July 4, 2026
  • Ukrainian national pleads guilty to role in Conti ransomware operation — Bleepingcomputer · June 12, 2026
  • FBI warns of in — Bleepingcomputer · May 27, 2026

CVSS v3.1 Breakdown