Latest in Gear

Image credit: solarseven via Getty Images

Ryuk ransomware banks $3.7 million in five months

It has the knack for staying dormant and focusing on big targets.
384 Shares
Share
Tweet
Share

Sponsored Links

solarseven via Getty Images

The Ryuk ransomware hasn't just causing grief for newspapers -- it's also quite lucrative for its operators. Researchers at CrowdStrike and FireEye both estimate that the code has produced the equivalent of $3.7 million in bitcoin since August, spread across 52 payments. The key, analysts note, is the willingness to be patient and focus on big targets.

The attacks typically start by infecting systems with TrickBot malware (typically through methods like spam email) that gains access and, importantly, lets the intruders study their targets to determine the money-making potential. They look for the most critical systems and, as Ars Technica noted, will even pass on launching the Ryuk ransomware if the organization isn't large enough. This scouting will be somewhat familiar if you've seen campaigns like SamSam (the ransomware that hit the city of Atlanta), and it's just as disconcerting.

The operators are patient, too. They'll wait as long as a "full year" to encrypt a victim's data and demand a ransom, FireEye said.

It's not certain just who the perpetrators are, but the two security groups don't believe the users are North Korean despite the name. Instead, CrowdStrike (which nicknamed the attackers Grim Spider) suggests they might be Russian based on internet addresses and the occasional language reference. Either way, it's clear that ransomware is becoming all too profitable and could be a serious problem for larger companies and governments in the near future.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
384 Shares
Share
Tweet
Share

Popular on Engadget

What's on TV: Super Bowl LIV, 'Terminator: Dark Fate' 4K and 'Uncut Gems'

What's on TV: Super Bowl LIV, 'Terminator: Dark Fate' 4K and 'Uncut Gems'

View
Fiat Chrysler's Android-based Uconnect 5 supports Alexa and wireless CarPlay

Fiat Chrysler's Android-based Uconnect 5 supports Alexa and wireless CarPlay

View
NASA picks space tourism outfit for its first commercial ISS module

NASA picks space tourism outfit for its first commercial ISS module

View
Billie Eilish proved anyone can access Grammy-winning gear

Billie Eilish proved anyone can access Grammy-winning gear

View
Atari-themed gaming hotels are coming to eight US cities

Atari-themed gaming hotels are coming to eight US cities

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr