Categories: News

The Ryuk ransomware operators made $150m in crypto

The researchers assume that the operators of the Ryuk ransomware managed to make more than $150m, in cryptocurrency. The security specialists studied the flaw of Bitcoin to the ransomware operators.

The AdvIntel company, together with the Hyas vendor came with a report which analyzed “61 crypto addresses attributed to Ryuk ransomware.”

The choice of the Ryuk operators

So, according to the researchers, the group sent most of the crypto it collected to Huobi and Binance. These are exchanges based in Asia, which could keep them away from the authorities, according to the authors of the analysis.

According to the research, “Huobi and Binance are interesting choices because they claim to comply with international financial laws.” Still, “they are willing to participate in legal requests”, but their structure “wouldn’t obligate them to comply.”

Also, according to the analysis, Huobi and Binance are Chinese companies. Still, they moved their business to more friendly to cryptocurrency exchanges” countries.

In order to build trust, both exchanges demand identity documents in order to allow crypto currencies exchange and transfers to banks. Still, “it isn’t clear if the documents they accept are scrutinized in any meaningful way.”

Also, the researchers managed to see “significant flows of cryptocurrency to a collection of addresses that are too small to be an established exchange.” So, their conclusion was that these might be “a crime service that exchanges cryptocurrency for local currency or another digital currency.”

Researchers managed to discover that the Ryuk authors asked their victims to pay the ransomware to a well-known broker. Then, the broker sends money to the hackers. Thus, the group receives “hundreds of thousands of dollars.”

No chat. Only two email addresses

The attackers used two email addresses on the free encrypted mail platform ProtonMail, in order to communicate with their victims.

But they chose the most valuable targets using a precursor malware, in order to assess their solvency. Thus, the experts consider that the attackers behind Ryuk act as a business.

So, they recommend organizations first of all to defend against the precursor malware, such as Emotet or Zloader. In order to do this, they should use multi-factor authentication. Also, they should avoid Microsoft Office macros in their environments.

Laurentiu Titei

Recent Posts

How To Fix Elden Ring Crashing on Startup

Is Elden Ring crashing on startup? This is a common problem for many PC gamers…

14 hours ago

How to Fix “Control Alt Delete Not Working” on Windows PC

Want to open Task Manager, change your password, log out, restart, or shut down your…

1 day ago

Mouse Right-Click Not Working in Windows 10? Here’s How to Fix It

Mouse right-click not working means frozen context menus and inaccessible shortcuts, which is frustrating. The…

2 days ago

Two Finger Scroll Not Working Windows 11/10? Here’s How to Fix It

Is the two-finger scroll not working? That’s a common problem on many laptops that develop…

3 days ago

Best Free Driver Updater Tools for Windows 10 and 11 in 2026

Are you on the lookout for the best free driver updater software? Look no further!…

5 days ago

Caps Lock Won’t Turn Off on Windows 10/11? Here’s How to Fix It

A smoothly functioning keyboard is crucial for a smooth experience. A stuck Caps Lock key…

5 days ago