Ragnar Locker, also known as RagnarLocker, is a financially motivated ransomware and extortion operation active since late 2019 or early 2020. It has targeted large enterprises and critical-infrastructure organizations, with confirmed victim activity in manufacturing, energy, financial services, government, information technology, health care, and consumer-facing businesses. U.S. authorities identified at least 52 affected organizations across 10 critical-infrastructure sectors as of January 2022. The operation uses double extortion: operators exfiltrate sensitive data, encrypt victim systems, and threaten publication through a leak site if negotiations fail. Ragnar Locker has also used DDoS attacks and direct public pressure, including social-media advertising directed at a victim, constituting additional extortion pressure. Its public leak infrastructure has been used to name victims and publish stolen data. Ragnar Locker operators have obtained access through exposed or compromised Remote Desktop Protocol services, managed-service-provider compromise, and exploitation of vulnerable remote-access infrastructure. Following compromise, they have used domain-level access, PowerShell, Group Policy, and remote administration tooling to move laterally and deploy payloads broadly. The malware enumerates hosts, drives, and volumes; stops backup, database, security, and remote-management services; terminates processes that could lock files; removes shadow copies; disables recovery features; and encrypts accessible local, removable, and network data. It performs locale checks and commonly avoids execution on systems configured for several former Soviet Union and nearby regional languages. A notable defense-evasion technique runs the ransomware from a VirtualBox-hosted legacy Windows virtual machine. The guest system mounts host and network storage as shared drives and encrypts them from within the virtual environment, causing encryption activity on the host to appear associated with the virtualization process rather than a directly executing ransomware binary. Ragnar Locker samples have also used packing, anti-debugging, victim-specific customization, hybrid Salsa20 and RSA encryption, and tailored ransom notes. Ragnar Locker publicly associated itself with the short-lived Maze Cartel branding alongside Maze and LockBit, although reporting characterized this as loose or primarily promotional cooperation rather than demonstrated shared operational control. In 2023, an international law-enforcement action disrupted Ragnar Locker infrastructure, seized its leak portal and servers, and resulted in arrests and searches across several European countries.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operators conducting big-game extortion against large companies and business users, encrypting files and stealing data beforehand for leak-based pressure, with additional use of DDoS coercion. The content also describes their use of a VirtualBox Windows XP VM to evade host-based antivirus during encryption.
Mentioned only as a previously linked Russia-aligned threat actor in background context about RansomHouse.
Conducted a ransomware attack against TAP Air Portugal and later leaked compromised data on a public dark web site.
Ransomware activity associated with the WIN-344VU98D3RU ISPsystem-derived hostname.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.