ArticleslgStudy

computer science

Ryuk (ransomware)

Ryuk (ransomware) is a computer science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Ryuk (ransomware) rather than just read about it. In short: Ryuk is a type of ransomware known for targeting large, public-entity Microsoft Windows cybersystems. It typically encrypts data on an infected system, rendering the data inaccessible until a ransom is paid in untraceable bitcoin.

Key takeaways

  • Ryuk (ransomware) belongs to computer science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Ryuk (ransomware) to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Ryuk (ransomware) from memory before moving on to harder problems.

Reference excerpt

Ryuk is a type of ransomware known for targeting large, public-entity Microsoft Windows cybersystems. It typically encrypts data on an infected system, rendering the data inaccessible until a ransom is paid in untraceable bitcoin. Ryuk is believed to be used by two or more criminal groups, most likely Russian or Ukrainian, who target organizations rather than individual consumers.

Origin The Ryuk ransomware first appeared in 2018. Ryuk was initially suspected to be of North Korean origin, then later thought to have been created by only one group or actor. It is now suspected that Ryuk has been created by multiple Russian criminal cartels. The criminal group known as Ryuk seeks primarily to extort ransom payments to decrypt the data that its malware has encrypted and as a result rendered useless. Following an attack on the Baltimore County (Maryland) school system in November 2020, a cybersecurity threat analyst said to the Baltimore Sun, the Ryuk criminal group "tends to be all business ... they just like to get the job done": to extort a large ransom payoff.

How it works In the UK, the National Cyber Security Centre notes that Ryuk uses Trickbot computer malware to install itself, once access is gained to a network's servers. It has the capability to defeat many anti-malware countermeasures that may be present and can completely disable a computer network. It can even seek out and disable backup files if kept on shared servers. Emotet is also used by Ryuk hackers to gain access to computers as the initial loader or "Trojan horse". The U.S. Cybersecurity and Infrastructure Security Agency (CISA) website provides detailed information on how Ryuk infects and takes control of a computer network, saying that access may be initially gained by: "... phishing campaigns that contain either links to malicious websites that host the malware or attachments with the malware. Loaders start the infection chain by distributing the payload; they deploy and execute the backdoor from the command and control server and install it on the victim’s machine". The phishing efforts generally contain malicious documents (or hyperlinks to them). When the victim enables it, a malicious macro or loader starts the infection sequence. Like many other ransomware families, Ryuk deletes shadow copy files and stops processes from the hardcoded list. Once Ryuk takes control of a system, it encrypts the stored data, making it impossible for users to access unless a ransom is paid by the victim in untraceable bitcoin. In many cases, days or weeks may elapse between the time hackers initially gain access to a system before the massive encryption occurs, as the criminals penetrate deeper into the network to inflict maximum damage. Ryuk is an especially pernicious type of malware because it also finds and encrypts network drives and resources. It also disables the System Restore feature of Microsoft Windows that would otherwise allow restoring the computer's system files, applications, and Windows Registry to their previous, unencrypted state. To combat these ransomware attacks, the U.S. Cyber Command initiated a counter-attack in September, 2020, to disconnect Trickbot from internet servers. Shortly thereafter, Microsoft invoked trademark law to seize Trickbot servers, disrupting a Ryuk botnet.

… excerpt ends here. Continue reading the full article.

Worked examples

Example 1 — a first encounter with Ryuk (ransomware)

Start with the simplest possible case. Write down what Ryuk (ransomware) claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In computer science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Ryuk (ransomware) before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Ryuk (ransomware) ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Ryuk (ransomware)

In research
Ryuk (ransomware) appears in computer science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Ryuk (ransomware) in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Ryuk (ransomware) is common in secondary-school and first-year university syllabi. It links to neighbouring topics 2020 in computing, Cyberattacks, Cybercrime, so understanding it makes those chapters shorter.
In everyday life
Look for Ryuk (ransomware) outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “Ryuk (ransomware)” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Ryuk (ransomware) in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Ryuk (ransomware) means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Ryuk (ransomware) out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Ryuk (ransomware) in simple terms?

Ryuk is a type of ransomware known for targeting large, public-entity Microsoft Windows cybersystems. It typically encrypts data on an infected system, rendering the data inaccessible until a ransom is paid in untraceable bitcoin.

Why does Ryuk (ransomware) matter?

Because it connects several computer science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Ryuk (ransomware)?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Ryuk (ransomware).

Tags

  • 2020 in computing
  • Cyberattacks
  • Cybercrime
  • Ransomware
  • Windows malware

Keep exploring