
A new malware has recently come to light , seemingly related to the Ryuk ransomware , which scans computer systems to steal sensitive personal and military information and then uploads it to an FTP site.
Although it shares many similarities with Ryuk, one key difference between them is that while Ryuk only encrypts files, this new malware steals files by uploading them to a website controlled by the attackers.
What exactly is happening?
The new malware triggers a scan of all files available on the infected machine. It looks for files with .doc or .xlsx extensions to steal.
The malware ignores files and folders such as Microsoft and Intel during scanning, while also skipping files with the .ryk extension. When a file with the .doc or .xlsx extension is detected, the malware first validates the file, checking if it contains a word document or spreadsheet.
The names of valid files are compared to a list of malware keywords, which includes words like “military,” “secret,” and “hidden.” This indicates that the malware specifically targets confidential data. It also checks for certain names, which are believed to come from the U.S. Social Security Administration’s list of the most popular names.
Similarities to Ryuk Ransomware
As has been observed, this new malware bears similarities to Ryuk ransomware, which has led to speculation that they could be related in some way.
There are code similarities between the new malware and Ryuk.
As already mentioned, the new malware omits Ryuk-related files, such as those with the .ryk extension, while also containing some references to Ryuk in its code.
However, Ryuk does not need any prerequisites to run, unlike the new malware that requires DLLs to run.
Security researchers are still looking for samples to analyze how hackers infect and launch an attack.
Although it appears that this malware is related to the infamous Ryuk ransomware, it is unclear whether the group behind Ryuk is responsible for this malware or if another group has gained access to the code and modified it.
