Back to Blog
Ryuk Ransomware Attacks: U.S. Organizations Targeted in Coordinated Campaign (April 2020)
ransomware

Ryuk Ransomware Attacks: U.S. Organizations Targeted in Coordinated Campaign (April 2020)

breachwire TeamJul 13, 20265 min read

Ryuk Ransomware: What Happened

Between November 2019 and April 2020, a coordinated ransomware campaign led by Karen Serobovich Vardanyan targeted multiple U.S. organizations, including a Michigan company, a technology company in Oregon, and a school in Texas. Vardanyan, who has since pleaded guilty in the United States, was directly involved in deploying Ryuk ransomware to compromise hundreds of servers and workstations across these entities. The attackers encrypted critical business and operational data, rendering systems inoperable and halting essential services. The campaign resulted in significant financial losses, with victims paying ransoms totaling approximately 1,610 Bitcoin, valued at over $15 million at the time. Notably, a single Michigan company paid 200 Bitcoin (over $1.1 million) to regain access to its data.

Attack Vector & Technical Detail

The Ryuk ransomware operators leveraged established intrusion tactics to gain initial access, followed by lateral movement and data encryption. While the specific initial access vector for these incidents is not detailed in the available data, Ryuk campaigns during this period commonly exploited phishing emails, credential theft, and exploitation of remote desktop services. The MITRE ATT&CK tactics observed include TA0006 (Credential Access), TA0005 (Defense Evasion), and TA0011 (Command and Control), indicating a multi-stage intrusion process. Attackers typically established persistence, escalated privileges, and deployed Ryuk payloads to maximize impact. No CVEs or specific IOCs were provided in the incident data, but Ryuk campaigns are known to use custom malware loaders and encrypted command-and-control channels, sometimes referencing leak sites such as the PrinzEugen leak site (Tor).

Confirmed Impact

The ransomware attacks disrupted operations at all three confirmed victim organizations in North America, encrypting critical data and halting business processes. The financial impact was severe: ransom payments exceeded $15 million in total, with individual organizations incurring seven-figure losses. The Michigan company’s $1.1 million ransom highlights the scale of operational dependency on digital assets. Beyond financial damage, these incidents likely triggered regulatory scrutiny, especially for the school in Texas, where student and staff data may have been at risk. The attacks underscore the vulnerability of diverse sectors—including education and technology—to targeted ransomware campaigns.

What This Means for Your Organization

The Ryuk incidents demonstrate that ransomware operators continue to target organizations of all sizes and sectors, exploiting weaknesses in credential management, remote access, and network segmentation. Organizations should prioritize multi-factor authentication, regular offline backups, and robust endpoint detection to mitigate similar threats. The use of MITRE tactics TA0006, TA0005, and TA0011 in these attacks highlights the need for comprehensive monitoring of credential access attempts, defense evasion techniques, and suspicious outbound connections. Proactive threat hunting and employee awareness training remain critical to reducing the risk of successful ransomware deployment.

Detection & Response

  • Immediate: Isolate affected systems and disconnect them from the network to prevent further spread of ransomware.
  • Hunt: Monitor for evidence of credential harvesting, lateral movement, and anomalous command-and-control traffic consistent with MITRE tactics TA0006, TA0005, and TA0011.
  • Patch: N/A (no specific CVEs identified in this incident).

Source: https://securityaffairs.com/195216/uncategorized/ryuk-ransomware-member-pleads-guilty-over-attacks-on-u-s-organizations.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: