
U.S. federal prosecutors say a Ryuk ransomware operation extracted more than $15 million in bitcoin from U.S. organizations. An Armenian national has admitted participating in attacks that disrupted hundreds of corporate systems, forcing victims to purchase decryption keys with cryptocurrency.
Prosecutors Detail Ryuk Ransomware Scheme
According to prosecutors, the operation infiltrated corporate networks and deployed Ryuk ransomware to encrypt critical data and halt business operations. Victims were instructed to send bitcoin (BTC) to designated wallets in exchange for decryption keys, with total proceeds from U.S. targets exceeding $15 million.
The Armenian defendant admitted involvement in the attacks, which authorities say were coordinated to maximize disruption and compel rapid payment. The case highlights the Department of Justice’s continued focus on ransomware groups that leverage cryptocurrencies to facilitate and conceal ransom payments.
How Victims Were Compelled to Pay
Ryuk attacks typically begin with unauthorized access to a network, followed by encryption of servers and workstations. Attackers then deliver a ransom note directing victims to pay in bitcoin to restore access. Payments are verified on-chain, after which decryption keys may be provided. The costs to victims can extend well beyond the ransom itself, including incident response, system restoration, and potential data loss or exposure.
Background on Ryuk and Crypto Ransoms
Ryuk is a ransomware strain first observed by security researchers in 2018, known for targeting large enterprises and public institutions. It has often been associated with “big game hunting,” where attackers pursue high-value organizations and demand substantial payments denominated in bitcoin. Law enforcement agencies and regulators continue to warn that paying ransoms can carry legal and security risks, and they encourage prompt reporting of incidents to authorities.