Ragnar is a ransomware threat actor and malware family referenced among major human-operated extortion groups active in the modern ransomware ecosystem. It is commonly discussed alongside operations such as LockBit, REvil, and Conti as part of the shift from opportunistic encryption campaigns to targeted intrusions that combine network compromise, data theft, and extortion pressure. Available high-confidence information here supports Ragnar’s identification as a ransomware actor, but does not directly establish detailed attribution, origin, victimology, or a distinct operational profile beyond its inclusion among notable ransomware families used for comparative analysis in extortion-focused reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware operation with an affiliate ecosystem; discussed only via an affiliate relationship, without specific victimology/TTP detail.
Mentioned only in passing as part of a comparison with LockBit.
Mentioned only as one of several comparative ransomware groups in leak-site statistics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.