ATT&CKReferencesCrowdStrike Ryuk January 2019

CrowdStrike Ryuk January 2019

Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.

Open the source

Techniques1

Groups1

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareRyuk

Ryuk has called GetIpNetTable in attempt to identify all mounted drives and hosts that have Address Resolution Protocol (ARP) entries.

T1036.005
Match Legitimate Resource Name or Location
MalwareRyuk

Ryuk has constructed legitimate appearing installation folder paths by calling GetWindowsDirectoryW and then inserting a null byte at the fourth character of the path. For Windows Vista or higher, the path would appear as C:\Users\Public.

T1055
Process Injection
MalwareRyuk

Ryuk has injected itself into remote processes to encrypt files using a combination of VirtualAlloc, WriteProcessMemory, and CreateRemoteThread.

T1057
Process Discovery
MalwareRyuk

Ryuk has called CreateToolhelp32Snapshot to enumerate all running processes.

T1059.003
Windows Command Shell
MalwareRyuk

Ryuk has used cmd.exe to create a Registry entry to establish persistence.

T1083
File and Directory Discovery
MalwareRyuk

Ryuk has enumerated files and folders on all mounted drives.

T1106
Native API
MalwareRyuk

Ryuk has used multiple native APIs including ShellExecuteW to run executables,GetWindowsDirectoryW to create folders, and VirtualAlloc, WriteProcessMemory, and CreateRemoteThread for process injection.

T1134
Access Token Manipulation
MalwareRyuk

Ryuk has attempted to adjust its token privileges to have the SeDebugPrivilege.

T1486
Data Encrypted for Impact
MalwareRyuk

Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory.

T1489
Service Stop
MalwareRyuk

Ryuk has called kill.bat for stopping services, disabling services and killing processes.

T1490
Inhibit System Recovery
MalwareRyuk

Ryuk has used vssadmin Delete Shadows /all /quiet to to delete volume shadow copies and vssadmin resize shadowstorage to force deletion of shadow copies created by third-party applications.

T1547.001
Registry Run Keys / Startup Folder
MalwareRyuk

Ryuk has used the Windows command line to create a Registry entry under HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run to establish persistence.

T1614.001
System Language Discovery
MalwareRyuk

Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage. If the machine has the value 0x419 (Russian), 0x422 (Ukrainian), or 0x423 (Belarusian), it stops execution.

T1680
Local Storage Discovery
MalwareRyuk

Ryuk has called GetLogicalDrives to emumerate all mounted drives, and GetDriveTypeW to determine the drive type.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.