Ragnar Locker is a ransomware family first observed in attacks in late December 2019 that targets enterprise organizations and uses double-extortion, combining data theft with file encryption and threats to leak stolen data. It has been associated with attacks against organizations including Energias de Portugal (EDP), Capcom, Campari, ADATA, Dassault Falcon Jet, the City of Antwerp, and TAP Air Portugal. FBI reporting cited in the content states Ragnar Locker had been deployed against at least 52 organizations across multiple U.S. critical infrastructure sectors since April 2020.
A notable Ragnar Locker tradecraft pattern is deployment of the ransomware from inside an Oracle VirtualBox Windows XP virtual machine to evade host-based security controls. In the described intrusion, operators used administrator-level domain access, PowerShell, and Windows Group Policy Objects for lateral movement, then executed msiexec.exe via a GPO task to download and silently install a crafted unsigned MSI package. That package contained an old VirtualBox build, a MicroXP virtual disk image, and the ransomware payload. The installer copied files to C:\Program Files (x86)\VirtualAppliances, launched va.exe and install.bat, registered VBoxC.dll and VBoxRT.dll, and created and started the VBoxDrv.sys driver service. The script stopped ShellHWDetection, deleted shadow copies with "vssadmin delete shadows /all /quiet," enumerated local disks, removable drives, and mapped network drives, configured them as VirtualBox shared folders, terminated selected processes and services, and launched the VM headlessly with VBoxHeadless.exe. Inside the guest VM, a startup script mounted host shared drives via \VBOXSVR and repeatedly executed C:\vrun.exe -vm to encrypt accessible host, network, and removable drives.
Observed behaviors in the content include encrypting files on local machines and mapped drives, attempting to connect to removable drives and mapped network drives, deleting volume shadow copies, creating and executing Windows services with sc.exe including for the VirtualBox driver, using regsvr32.exe to execute VirtualBox components, and attempting to terminate or stop processes and services associated with endpoint security products. Sophos root cause analysis logs cited attempts to kill SavService.exe and stop services such as mysql. Ragnar Locker also checks the Windows API GetLocaleInfoW before executing malicious code and does not encrypt files if it detects a former Soviet country.
The content states Ragnar Locker is not a typical ransomware-as-a-service operation and has been described as semi-private, sometimes working with outside pentesters for network breaches. Prior footholds were reported to include managed service provider compromises and attacks on exposed Windows RDP connections. The group has also conducted pure data-theft extortion without deploying an encryptor. On October 19, 2023, international law enforcement seized Ragnar Locker's Tor negotiation and data leak sites, and the content also references the arrest of a Ragnar Locker developer in Paris.
The content further notes ecosystem overlap with Dark Angels, a Russian-speaking cybercriminal group that has used Ragnar Locker variants and Ragnar Locker's original ESXi encryptor in some operations. More recent Ragnar Locker activity was reported to include a VMware ESXi encryptor based on Babuk's leaked source code.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In a recently detected attack, Ragnar Locker ransomware was deployed inside an Oracle VirtualBox Windows XP virtual machine.
The Russian-speaking cybercriminal group has a dark web site under a different name, dubbed "Dunghill Leak," and doesn't have its own ransomware; Dark Angels has used variants of other ransomware such as Ragnar Locker.
Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining administrator-level access to the domain... they have used native Windows administrative tools such as Powershell and Windows Group Policy Objects (GPOs) to move laterally across the network to Windows clients and servers.
APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution. | During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The script’s first task is to register and run the necessary VirtualBox application extensions VBoxC.dll and VBoxRT.dll, and the VirtualBox driver VboxDrv.sys: regsvr32 /S "%binpath%\VboxC.dll" rundll32 "%binpath%\VBoxRT.dll,RTR3Init"
"Anchor can create and execute services to load its payload"; "APT32's backdoor has used Windows services as a way to execute its malicious payload"; "Ragnar Locker has used sc.exe to execute a service that it creates"; "Shamoon creates a new service named 'ntssrv' to execute the payload"
In past attacks, the Ragnar Locker group has used exploits of managed service providers or attacks on Windows Remote Desktop Protocol (RDP) connections to gain a foothold on targeted networks.
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
In the detected attack, the Ragnar Locker actors used a GPO task to execute Microsoft Installer (msiexec.exe), passing parameters to download and silently install a 122 MB crafted, unsigned MSI package from a remote web server.
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
The script executes a command to delete the targeted PC’s volume shadow copies, so victims cannot restore older unencrypted versions of their files: vssadmin delete shadows /all /quiet
“AppleJeus delivered components using a Windows Installer package (.msi)… executed the 3CXDesktopApp.exe…”, “APT38 has used msiexec.exe to execute malicious files.”, “Rancor has used msiexec to download and execute malicious installer files over HTTP.”, “TA505 has used msiexec to download and execute malicious Windows Installer files.”
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory. ... Raspberry Robin uses regsvr32.exe execution without any command line parameters for command and control requests to IP addresses associated with Tor nodes.
A new ransomware attack method takes defense evasion to a new level—deploying as a full virtual machine on each targeted device to hide the ransomware from view... Since the vrun.exe ransomware application runs inside the virtual guest machine, its process and behaviors can run unhindered, because they’re out of reach for security software on the physical host machine.
Another text file contains services names. These are tailored to the victim organization’s network environment, including process and service names belonging to endpoint protection software.
The install.bat command goes through a list of process names and terminates these processes so any files they have open are unlocked and become accessible for encryption. This list of 50 entries consists of mainly line-of-business applications, database, remote management and backup applications.
The VM is configured with 256 MB RAM, 1 CPU, a single 299 MB HDD file micro.vdi and an Intel PRO/1000 network adapter attached to NAT.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
The install.bat script then goes on to enumerate all local disks, connected removable drives and mapped network drives on the physical machine... This means that the ransomware in the guest environment can now fully access the host’s local disks, mapped network and removable drives.
A new ransomware attack method takes defense evasion to a new level—deploying as a full virtual machine on each targeted device to hide the ransomware from view... Since the vrun.exe ransomware application runs inside the virtual guest machine, its process and behaviors can run unhindered, because they’re out of reach for security software on the physical host machine.
"Amadey does not run any tasks or install additional malware if the victim machine is based in Russia"; "DarkGate queries system locale information... determine if the malware is executing in Russian-speaking countries"; "Ragnar Locker checks... GetLocaleInfoW and doesn't encrypt files if it finds a former Soviet country"; "Saint Bot has conducted system locale checks..."
In past attacks, the Ragnar Locker group has used exploits of managed service providers or attacks on Windows Remote Desktop Protocol (RDP) connections to gain a foothold on targeted networks.
After gaining administrator-level access to the domain... they have used native Windows administrative tools such as Powershell and Windows Group Policy Objects (GPOs) to move laterally across the network to Windows clients and servers. In the detected attack, the Ragnar Locker actors used a GPO task to execute Microsoft Installer (msiexec.exe), passing parameters to download and silently install a 122 MB crafted, unsigned MSI package from a remote web server.
who later leaked the compromised data via a public dark web site
The adversaries behind Ragnar Locker have been known to steal data from targeted networks prior to launching ransomware... claimed to have stolen 10 terabytes of sensitive company data, demanding a payment of 1,580 Bitcoin and threatening to release the data if the ransom was not paid.
Attempts to terminate Anti-Virus process: taskkill /IM SavService.exe /F... Another text file contains services names... including process and service names belonging to endpoint protection software.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that encrypts files and uses a defense-evasion technique by running from inside a VirtualBox-hosted Windows XP virtual machine. The operators also steal data before encryption to pressure victims into paying and use administrative tools, GPOs, and MSI deployment for lateral movement and execution.
Ragnar Locker is a ransomware family used by Dark Angels in some operations; the article notes Dark Angels does not have its own ransomware and instead has used variants of Ragnar Locker.
Ragnar Locker is a ransomware group known for using Bring-Your-Own-Virtual-Machine (BYOVM) techniques to evade detection and facilitate ransomware deployment.
Ransomware that deletes volume shadow copies using vssadmin.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.