Defense Evasion
- VirtualBox
RagnarLocker is a Windows ransomware family and associated criminal operation active since 2020, principally targeting large enterprises and critical-infrastructure organizations, including manufacturing, energy, financial services, government, information technology, and healthcare.
Profile source: Mallory opens in a new tabRagnarLocker
RagnarLocker is a Windows ransomware family and associated criminal operation active since 2020, principally targeting large enterprises and critical-infrastructure organizations, including manufacturing, energy, financial services, government, information technology, and healthcare. It encrypts victim data and employs double extortion by stealing data and threatening public disclosure; operators have also been associated with DDoS-based pressure tactics. The operation has been commonly associated with Viking Spider, while affiliates linked to UNC2447 have also deployed RagnarLocker.
RagnarLocker uses layered packing and obfuscation, including VMProtect and UPX, and performs locale checks that cause execution to stop on systems configured for several CIS-region locales. Before encryption, it collects host-identification information, enumerates storage volumes and services, terminates backup and remote-management services, and deletes Volume Shadow Copies. It selectively excludes system-related directories and executable or system-file types to preserve host operability. File encryption uses symmetric encryption with RSA-2048 protection of encryption material, and encrypted files receive a victim-specific extension and marker.
A notable evasion technique is execution from an attacker-deployed Oracle VirtualBox virtual machine, including a custom Windows XP guest. The virtual machine accesses host files through shared folders, allowing encryption activity to occur from the guest environment and reducing visibility to host-based security products. RagnarLocker incidents have also involved compromise of exposed remote-access infrastructure, including unpatched VPN appliances, followed by enterprise-wide post-compromise activity and ransomware deployment. International law-enforcement action disrupted RagnarLocker infrastructure and arrested suspected participants in 2023.
Reported operators
A 2021 report by Mandiant notes the group had previously deployed RagnarLocker.
In November 2020, the company announced it was hit by a crippling ransomware attack. The attack was orchestrated by the RagnarLocker group.
MITRE ATT&CK
Reporting
Maze emerged as one of the most influential ransomware operations targeting businesses, corporations, and municipal organizations, combining file encryption with data theft and public leak threats to force victims into paying. The group first spread through exploit kits and malicious spam, then shifted to more targeted intrusions using spear-phishing, exploitation of internet-facing services such as Citrix ADC/NetScaler and Pulse Secure VPN, and attacks against weak RDP credentials. Researchers described Maze as a C/C++ Windows PE malware with obfuscation, anti-analysis features, and a layered encryption scheme that paired ChaCha with RSA-2048. The operation also expanded its influence by forming a ransomware cartel with LockBit and RagnarLocker, sharing leak infrastructure and tradecraft in a model that helped normalize double-extortion tactics across the broader ransomware ecosystem.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.