Ryuk is a ransomware group that first emerged in August 2018, evolving from the Hermes ransomware codebase. Initially known for its highly targeted, human-operated attacks, Ryuk adopted worm-like capabilities in a 2021 variant, enabling faster self-propagation across networks. The group operates with a clear financial motivation, primarily engaging in "big-game hunting" by targeting large organizations and public sector entities capable of paying substantial ransoms. Assessed with high confidence to be operated by the Russian cybercriminal collective Wizard Spider, Ryuk distinguishes itself by conducting extensive reconnaissance and deploying its ransomware manually after initial compromise, often leveraging established malware like Emotet and TrickBot for network access and lateral movement. While not a ransomware-as-a-service (RaaS) in the traditional sense, multiple threat actors have been observed using the Ryuk ransomware, sometimes affiliated with the Wizard Spider group or as cl