Skip to content

RagnarLocker

RagnarLocker is a Windows ransomware family and associated criminal operation active since 2020, principally targeting large enterprises and critical-infrastructure organizations, including manufacturing, energy, financial services, government, information technology, and healthcare.

Profile source: Mallory opens in a new tab

RagnarLocker

Family profile

RagnarLocker is a Windows ransomware family and associated criminal operation active since 2020, principally targeting large enterprises and critical-infrastructure organizations, including manufacturing, energy, financial services, government, information technology, and healthcare. It encrypts victim data and employs double extortion by stealing data and threatening public disclosure; operators have also been associated with DDoS-based pressure tactics. The operation has been commonly associated with Viking Spider, while affiliates linked to UNC2447 have also deployed RagnarLocker.

RagnarLocker uses layered packing and obfuscation, including VMProtect and UPX, and performs locale checks that cause execution to stop on systems configured for several CIS-region locales. Before encryption, it collects host-identification information, enumerates storage volumes and services, terminates backup and remote-management services, and deletes Volume Shadow Copies. It selectively excludes system-related directories and executable or system-file types to preserve host operability. File encryption uses symmetric encryption with RSA-2048 protection of encryption material, and encrypted files receive a victim-specific extension and marker.

A notable evasion technique is execution from an attacker-deployed Oracle VirtualBox virtual machine, including a custom Windows XP guest. The virtual machine accesses host files through shared folders, allowing encryption activity to occur from the guest environment and reducing visibility to host-based security products. RagnarLocker incidents have also involved compromise of exposed remote-access infrastructure, including unpatched VPN appliances, followed by enterprise-wide post-compromise activity and ransomware deployment. International law-enforcement action disrupted RagnarLocker infrastructure and arrested suspected participants in 2023.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Reconnaissance

Operational record

1
YARA rules
2
Ransom notes
4
Leak sites
2 available

Defense Evasion

  • VirtualBox

Discovery Enum

  • Advanced Port Scanner
  • Dsquery
  • PsInfo
  • SoftPerfect LanSearchPro

LOLBAS

  • PsExec
  • WMIC

Offsec

  • Cobalt Strike

RMM Tools

  • AnyDesk
  • Remote Manipulator System (RMS)
  • RemoteUtilities

Reported operators

Threat actors

2 named in public reporting
UNC2447

A 2021 report by Mandiant notes the group had previously deployed RagnarLocker.

VIKING SPIDER

In November 2020, the company announced it was hit by a crippling ransomware attack. The attack was orchestrated by the RagnarLocker group.

MITRE ATT&CK

RagnarLocker in ATT&CK

39 distinct techniques

Reporting

Research mentioning RagnarLocker

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.