Security News > 2021 > March > Ryuk Ransomware With Worm-Like Capabilities Spotted in the Wild

Ryuk Ransomware With Worm-Like Capabilities Spotted in the Wild
2021-03-02 04:40

In early 2021, security researchers identified a variant of the infamous Ryuk ransomware that is capable of lateral movement within the infected networks.

Active since at least 2018 and believed to be operated by Russian cyber-criminals, the Ryuk ransomware has been involved in numerous high-profile attacks and researchers estimate the enterprise is worth $150 million.

In a recently published report, the French National Agency for the Security of Information Systems said that it identified one Ryuk sample that could spread automatically within infected networks earlier this year.

The ransomware has long relied on the use of other malware for the initial deployment and did not show signs of worm-like capabilities before, although it was able to encrypt data on network shares and removable drives.

The newly identified version of Ryuk has all of the functions typically found within the ransomware, with the ability to replicate itself over the local network added on top.

To propagate to other machines, the ransomware copies the executable on identified network shares with a rep.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/Z4DnFVy8yYA/ryuk-ransomware-worm-capabilities-spotted-wild