Rewterz
Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
September 11, 2022
Rewterz
Rewterz Threat Alert – Lampion Malware Returns Using WeTransfer As Part Of Their Phishing Attacks – Active IOCs
September 11, 2022

Rewterz Threat Alert – Ryuk Ransomware – Active IOCs

Severity

High

Analysis Summary

Ryuk Ransomware is a ransomware family that was first found in the wild in August 2018. It is one of the most virulent ransomware strains on the market. Ryuk has been observed being used to attack companies or professional environments. This ransomware can lock your files or systems and hold them hostage for ransom. Ryuk targets high-profile enterprises in order to obtain essential information that will impair the victim’s operations.

Ryuk is a form of ransomware used in targeted attacks, in which threat actors encrypt important data to demand big ransom payments. Emotet or TrickBot malware is widely used to spread Ryuk ransomware. Ryuk’s code is comparable to that of the Hermes ransomware. The Ryuk ransomware is believed to be operated by the Russian cybercriminal group WIZARD SPIDER.

Impact

  • File encryption
  • Privilege Escalation 
  • Information Theft 
  • Data Exfiltration 
  • Network Compromise

Indicators of Compromise

MD5

  • c24f6144e905b717a372c529d969611e

SHA-256

  • 94ef44e3f7be172fb47203eb942e4601f1a96cb4bfd37e055fd6cf39b5db49a6

SHA-1

  • 0a297e9e5c807c06ad10f4f746f4f9e256df6743

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.
  • Maintain cyber hygiene by updating your anti-virus software and implementing a patch management lifecycle.
  • Maintain Offline Backups – In a ransomware attack, the adversary will often delete or encrypt backups if they have access to them. That’s why it’s important to keep offline (preferably off-site), encrypted backups of data and test them regularly.
  • Emails from unknown senders should always be treated with caution.
  • Never trust or open ” links and attachments received from unknown sources/senders.