Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareRyuk | Ryuk has called |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRyuk | Ryuk has constructed legitimate appearing installation folder paths by calling |
| T1055 Process Injection |
MalwareRyuk | Ryuk has injected itself into remote processes to encrypt files using a combination of |
| T1057 Process Discovery |
MalwareRyuk | Ryuk has called |
| T1059.003 Windows Command Shell |
MalwareRyuk | Ryuk has used |
| T1083 File and Directory Discovery |
MalwareRyuk | Ryuk has enumerated files and folders on all mounted drives. |
| T1106 Native API |
MalwareRyuk | Ryuk has used multiple native APIs including |
| T1134 Access Token Manipulation |
MalwareRyuk | Ryuk has attempted to adjust its token privileges to have the |
| T1486 Data Encrypted for Impact |
MalwareRyuk | Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory. |
| T1489 Service Stop |
MalwareRyuk | Ryuk has called |
| T1490 Inhibit System Recovery |
MalwareRyuk | Ryuk has used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRyuk | Ryuk has used the Windows command line to create a Registry entry under |
| T1614.001 System Language Discovery |
MalwareRyuk | Ryuk has been observed to query the registry key |
| T1680 Local Storage Discovery |
MalwareRyuk | Ryuk has called |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.