Avis de sécurité

Menaces et incidents


? The Ryuk Ransomware (26 février 2021)

Publié le 26 février 2021 15:00

French version: ????????

 

First observed in August 2018, the Ryuk ransomware has since been used in Big Game Hunting operations. It is characterized by the use of different infection chains and the extreme speed of the Bazar-Ryuk chain, as well as the absence of a dedicated leak site. A Ryuk variant with worm-like capabilities, allowing it to spread automatically over the local network, was recently discovered during incident response. Please see Appendices of the report for additional information on this variant and how to contain its propagation.

This updated report provides a synthesis of ANSSI’s knowledge on Ryuk.

Indicators of compromise are available in structured formats on the page CERTFR-2020-IOC-005.

 

DOWNLOAD THE REPORT

LIENS ASSOCIES


Inscrivez-vous à la newsletter CSIRT pour recevoir périodiquement les publications

Contact

contact@csirt-universitaire.org
+221 78 601 64 64
BP: XXX - Sénégal