Ragnar Locker is a targeted Windows ransomware family active since late 2019 and associated with the Ragnar Locker/Monstrous Mantis criminal operation. It is used in enterprise intrusions, including against critical-infrastructure organizations in manufacturing, energy, financial services, government, information technology, and telecommunications. The operation uses double extortion: operators steal sensitive data, encrypt victim systems, and threaten publication through leak infrastructure if payment is withheld. DDoS pressure has also been used in extortion activity.
Ragnar Locker is customized for individual victims and encrypts files with Salsa20-based encryption while using an RSA public key to protect encryption material. It enumerates disks and volumes, force-maps accessible volumes, terminates selected database, backup, security, remote-management, and line-of-business processes and services, removes shadow copies, and disables Windows recovery mechanisms. It avoids execution on systems configured with specified former Soviet Union and nearby regional language settings.
A notable defense-evasion method deploys the ransomware within a Windows XP virtual machine using VirtualBox. The guest is given writable access to local, removable, and mapped network drives, causing encryption activity on the host to appear to originate from the legitimate virtualization process rather than directly from the ransomware. Operators have used PowerShell and Group Policy for deployment and lateral movement after obtaining privileged domain access. Observed initial-access methods include compromise of managed service providers and attacks involving exposed Remote Desktop Protocol services. Ragnar Locker has also abused signed Windows utilities, including Msiexec, Regsvr32, and Rundll32, to execute VirtualBox-related components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
To elevate privileges, the attacker exploits the CVE-2017-0213 vulnerability in the Windows COM Aggregate Marshaler to run arbitrary code with elevated privileges. | Analysis of Ragnar Locker Ransomware. First discovered in April 2020. Uses the increasingly popular “double extortion” tactic, in which the attacker first exfiltrates sensitive data, then triggers the encryption attack, threatening to leak the stolen data if the target refuses to pay the ransom.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The organization in question came to Sophos Rapid Response after falling victim to a Ragnar Locker attack in early 2020.
In a recently detected attack, Ragnar Locker ransomware was deployed inside an Oracle VirtualBox Windows XP virtual machine.
The Russian-speaking cybercriminal group has a dark web site under a different name, dubbed "Dunghill Leak," and doesn't have its own ransomware; Dark Angels has used variants of other ransomware such as Ragnar Locker.
Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining administrator-level access... they have used native Windows administrative tools such as Powershell and Windows Group Policy Objects (GPOs) to move laterally across the network.
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
In past attacks, the Ragnar Locker group has used exploits of managed service providers or attacks on Windows Remote Desktop Protocol (RDP) connections to gain a foothold on targeted networks.
ntdll.dllのDbgUiRemoteBreakinの先頭5バイトを自身のオリジナルのフック関数へジャンプするようにメモリを書き換えます。
The Ragnar Locker actors used a GPO task to execute Microsoft Installer (msiexec.exe), passing parameters to download and silently install a 122 MB crafted, unsigned MSI package.
暗号化ファイルの拡張子変更は、以下のようにMoveFileExを使用し、ファイル移動させることでリネームします。
ntdll.dllのDbgUiRemoteBreakinの先頭5バイトを自身のオリジナルのフック関数へジャンプするようにメモリを書き換えます。
Microsoft Installer (msiexec.exe) executes MSI package... [the GPO task] execute[s] Microsoft Installer (msiexec.exe), passing parameters to download and silently install a 122 MB crafted, unsigned MSI package.
AppleSeed can call regsvr32.exe for execution. APT19 used Regsvr32 to bypass application control techniques. APT32 created a Scheduled Task/Job that used regsvr32.exe to execute a COM scriptlet that dynamically downloaded a backdoor and injected it into memory.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
Ragnar Locker ransomware was deployed inside an Oracle VirtualBox Windows XP virtual machine to hide the ransomware from view.
ローカルドライブとしてマッピングされていないボリュームを発見した場合、強制的にローカルドライブとしてマッピングした上で、暗号化を行います。
Ragnar Locker ransomware was deployed inside an Oracle VirtualBox Windows XP virtual machine to hide the ransomware from view.
Ragnar Lockerは、実行された環境がロシア語など特定の言語情報が設定された端末であった場合、感染を行いません。具体的には、GetLocaleInfoにより感染端末の言語設定情報を取得し、特定の国リストと比較した結果、同じであった場合、最終的に自身のプロセスを強制終了させます。
Before encrypting a victim's network, most network-targeting ransomware operations will steal a victim's unencrypted files.
The ransomware in the guest environment can now fully access the host’s local disks, mapped network and removable drives... the ransomware encrypts the files on all available mapped network drives.
The install.bat command goes through a list of process names and terminates these processes... Another text file contains services names... including process and service names belonging to endpoint protection software.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
71 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware deployed within a VirtualBox-hosted Windows XP guest VM to evade host-based security controls. It maps the physical host's local, removable, and network drives into the guest, terminates selected processes and services, deletes volume shadow copies, encrypts accessible files, and drops a victim-specific ransom note. Operators also exfiltrate data before encryption to support extortion.
Ransomware that deploys a full virtual machine on targeted devices to evade security tools.
Ransomware noted for deploying a VirtualBox VM to hide malicious processes from scanners and avoid AMSI-related visibility.
Ransomware used in a prior attack against the victim organization, manually deployed across hundreds of computers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.