One of the most notorious ransomware gangs, targeting large companies and organizations, managed to extort $34 million from a single victim in exchange for the decryption key that “liberated” their computers from ransomware. This achievement belongs to the hackers behind the Ryuk ransomware.

These hackers manage to breach corporate networks, spread to different devices , and cover their tracks before unleashing the Ryuk ransomware.
The group is also known as group “one” and is ruthless with victims . It often uses the Trickbot botnet in the first stage of the attack.
According to Vitali Kremez of Advanced Intelligence, recent victims of Ryuk group “one” include companies in the technology, healthcare, energy, financial services sectors. Government agencies.
Healthcare and social service organizations are one of the favorite targets of the Ryuk gang (13% of attacks).
Ryuk is one of the most popular ransomware. According to a report by Check Point, the gang carried out an average of 20 attacks per week during the third quarter of 2020.
Some of the gang's most recent victims include: Universal Health Services (UHS), Sopra Steria, law firm Seyfarth Shaw, furniture manufacturer Steelcase, and hospitals in Brooklyn and Vermont.
The researcher says that hackers are demanding an average of 48 bitcoins (nearly $750,000). It is said that during 2018, the criminals made at least $150 million.
Kremez published a report in which he states that the Russian ransomware gang is very tough in its negotiations and rarely shows leniency. The largest confirmed payment it received was 2,200 bitcoins, which is close to $34 million today.

15-step attack
Analyzing the attacks, Kremez notes that the Ryuk ransomware gang follows 15 steps to find available computers on the network, steal admin credentials , and deploy the Ryuk ransomware.
Hackers use software that is also used by red-teams to control network security :
- Mimikatz: post-exploitation tool for stealing credentials from memory
- PowerShell PowerSploit: a collection of PowerShell scripts
- LaZagne: similar to Mimikatz, used to harvest passwords from locally stored software
- AdFind: Active Directory query tool
- Bloodhound: post-exploitation tool
- PsExec: allows executing processes on remote systems
The attack chain begins by executing the Cobalt Strike “invoke” command to execute the “DACheck.ps1” script. In this way, the hackers check whether the current user is a member of a Domain Admin group.
From there, passwords are retrieved via Mimikatz, the network is mapped, and hosts are identified after scanning for FTP, SSH, SMB, RDP, and VNC protocols.
Here is the Ryuk ransomware gang's 15-step attack, according to Kremez:
- Domain admin check via the “Invoke-DACheck” script
- Collecting passwords via Mimikatz “mimikatz's sekurlsa::logonpasswords”
- Reset token and create token for administrative comment from Mimikatz command output
- Checking the network via “net view”
- Scan for FTP, SSH, SMB, RDP, VNC protocols
- Create a list for accessing available hosts
- Downloading the “AdFind” kit with the batch script “adf.bat” from “net view”
- Displaying the antivirus name via the “WMIC” command
- Download the “LaZagne” tool to scan the host computer
- Removing the tool
- Running ADFind and saving the outputs
- Delete AdFind and download the ouputs
- Granting access to Ryuk ransomware
- Downloading the remote execution software “PSExec” and uninstalling the antivirus
- Downloading batch scripts and executing Ryuk ransomware
Source: Bleeping Computer
