Trickbot
If you find evidence of Ryuk, but not Emotet, it might be worth looking for Trickbot as well, Nahorney said. Both Emotet and Trickbot have been seen deploying Ryuk in attacks, at times in coordination, and other times separately.
“Sure enough, Trickbot follows a similar pattern in terms of DNS activity, lower in the first half of the year, busy in August and September, then quiet in October,” he said. “However, Trickbot was active between November and December, when Emotet was not, likely contributing to the phenomenal increase in Ryuk activity during these two months.”