Ragnarok is a ransomware threat actor active since at least January 2020. The group operated a leak site and used extortion pressure by threatening to publish stolen unencrypted victim data, indicating a double-extortion model combining file encryption with data-theft coercion. Ragnarok gained particular attention for exploiting the Citrix ADC vulnerability CVE-2019-19781 during its operations. Reported victims spanned multiple countries and sectors, including manufacturing and legal services. In August 2021, the group appeared to abruptly cease operations and released a master decryption capability that enabled recovery of files encrypted by its ransomware across multiple file-extension variants. Separate reporting also noted an unverified underground access-sale post using the alias “Ragnarok,” but that activity is not sufficient to attribute broader intrusion-trade operations to the ransomware group with high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Access broker-style actor advertising alleged local administrator access into a large enterprise environment in East Asia; claims bot-based access and ability to execute CMD; authenticity unverified.
Ransomware operation that appears to have shut down and released a master decryption key for victims. The group previously used leak-site extortion and had exploited a Citrix ADC vulnerability in earlier operations.
Mentioned only as one of several comparative ransomware groups in leak-site statistics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.