Between 2018 and 2021, the most common path to a devastating ransomware infection followed a three-stage chain: Emotet delivered TrickBot, which delivered Ryuk ransomware. Each component had its own operators, its own criminal business model, and its own infrastructure - but they worked together in a loosely coordinated cybercrime supply chain that extracted hundreds of millions of dollars from hospitals, schools, governments, and businesses worldwide. Understanding this chain is essential to understanding how modern enterprise ransomware works, because the same layered delivery model that Emotet pioneered is still the dominant approach.
Emotet began life in 2014 as a banking trojan designed to steal credentials from online banking sessions. By 2018, its operators had pivoted to a different business model: selling access. Emotet had evolved into the world's most capable malware distribution platform - a "malware as a service" botnet that would, for a fee, deliver any malware to any system already infected with Emotet. TrickBot was among its biggest customers. When Emotet infected a corporate network and TrickBot was deployed, TrickBot's reconnaissance capabilities identified high-value targets. The Ryuk ransomware group (known to researchers as WIZARD SPIDER) then paid TrickBot's operators for access to those high-value networks and deployed their ransomware manually through TrickBot's existing foothold.
Emotet: The Perfect Delivery Mechanism
Emotet spread primarily through malicious email campaigns - hundreds of thousands of emails per day during peak operation. The emails were notable for their quality: Emotet hijacked existing email threads, inserting malicious replies that appeared to continue legitimate conversations between real people. If an Emotet-infected machine had a conversation in its email history between Alice and Bob, Emotet would send an email appearing to come from Bob, replying to the actual prior conversation, containing a malicious attachment or link.
This "email thread hijacking" made Emotet phishing emails extraordinarily effective. Recipients saw email from a known contact continuing an actual conversation they had participated in - far more convincing than generic phishing. The malicious documents typically contained obfuscated macros that, when enabled, downloaded and executed the Emotet payload. Emotet then harvested the new machine's email contacts and history, expanding both the contact pool for future phishing and the scope of thread hijacking available.
Once inside a network, Emotet used various techniques to spread laterally: exploiting EternalBlue (MS17-010) on unpatched systems, brute-forcing SMB credentials using a built-in password list, and leveraging WMI (Windows Management Instrumentation) and scheduled tasks for execution on discovered hosts. A single infected employee could result in Emotet spreading to hundreds of workstations across a corporate network within hours.
TrickBot: The Reconnaissance and Access Broker
TrickBot (operated by WIZARD SPIDER alongside Ryuk) began as a banking trojan in 2016 but evolved into a comprehensive network reconnaissance and persistence tool. Where Emotet spread broadly and quickly, TrickBot moved more carefully - its goal was not maximum spread but maximum intelligence gathering about the specific network it inhabited.
TrickBot's modules collected: domain credentials (via keylogging and browser credential theft), Active Directory structure (enumerating domain controllers, organizational units, user accounts), network topology (mapping subnets, live hosts, accessible services), and browser-stored credentials. Its "pwgrab" module collected credentials from Chrome, Firefox, IE, and Edge. Its "networkDll" module mapped the network. A dedicated module targeted Citrix and Remote Desktop environments. TrickBot operators would analyze this intelligence and, for networks meeting their criteria (sufficiently large, sufficiently valuable), sell manual access to the Ryuk ransomware operators.
The Ryuk operators would then use TrickBot's existing access - already deep inside the network with domain credentials in hand - to move to domain controller access, disable backup systems and security software, and deploy Ryuk ransomware to every accessible machine simultaneously.
Ryuk's Targets and Impact
Ryuk ransomware (named for a character from the manga Death Note, as was common among ransomware operators in this period) was deployed exclusively against high-value enterprise targets. The operators pre-screened victims through the TrickBot intelligence before deploying, looking for organizations with large enough revenues to pay multimillion-dollar ransoms and sufficient dependence on their IT systems to face catastrophic operational impact.
The healthcare sector was hit particularly hard. Universal Health Services suffered a nationwide Ryuk attack in September 2020, with 400+ hospitals across the US and UK losing access to systems for weeks. Staff had to revert to paper records, ambulances were diverted, surgeries were delayed. The recovery cost was estimated at $67 million. Ryuk attacks against hospitals during COVID-19 directly endangered patient care at a moment of maximum healthcare system stress.
School districts, municipal governments (the City of New Orleans was hit in December 2019, costing $7 million), and logistics companies were also frequent targets. Total Ryuk ransom payments through 2021 are estimated at over $150 million based on tracked blockchain transactions, with actual losses from downtime and recovery far exceeding that figure.