Ragnarok is a Windows ransomware family active since at least early 2020 and used in targeted intrusions against enterprise environments. It has been associated with exploitation of internet-facing infrastructure, notably Citrix ADC systems vulnerable to CVE-2019-19781, and was also observed in attempts to propagate from compromised firewall appliances into internal Windows networks. After initial footholds, operators used scripts and exploit chains to identify and compromise additional Windows hosts, including attempts to leverage EternalBlue and DoublePulsar for lateral spread to older unpatched systems.
Ragnarok encrypts files using symmetric encryption with the per-file or session key protected by RSA, and appends its own extension to encrypted data. It drops ransom notes in affected directories and has been used in double-extortion operations in which victims were pressured with threats to leak stolen data. The malware includes logic to avoid execution or encryption on systems configured for multiple CIS locales and certain Chinese language settings, a behavior commonly interpreted as geofencing. It also contains anti-recovery and defense-impairment functionality, including attempts to disable Windows Defender protections, delete shadow copies, disable startup recovery, and turn off the Windows Firewall.
Technical analyses have shown that some Ragnarok samples implement a single-instance check by deriving a host-specific fingerprint from system values and creating a named Windows event object; if the event already exists, the malware terminates after repeated checks. This behavior enabled proof-of-concept preventive tooling for some variants, though it is not universal across all samples. Ragnarok has also been observed skipping selected system-critical files and directories to preserve host stability during encryption.
Victimology has included organizations across multiple countries and sectors, including manufacturing, legal services, government-related environments, and other enterprises. Public reporting also tied Ragnarok to disruptive incidents affecting public-sector operations. The ransomware operation later appeared to shut down and released a master decryption capability, enabling development of universal decryptors for victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the attacker’s hotfix application would have attempted to leverage the EternalBlue network-level remote code execution exploit and DoublePulsar kernel- and user-land shellcode, to deliver, inject, and execute the architecture-appropriate DLL directly into the memory of the Windows explorer.exe process on the targeted computer. | The attacker’s so-called “hotfix” is a Windows ransomware called Ragnarok. This ransomware is now connected to at least two attack campaigns targeting networked devices.
A new ransomware called Ragnarok has been detected being used in targeted attacks against unpatched Citrix ADC servers vulnerable to the CVE-2019-19781 exploit. Last week, FireEye released a report about new attacks exploiting the now patched Citrix ADC vulnerability to install the new Ragnarok Ransomware on vulnerable networks. | A new ransomware called Ragnarok has been detected being used in targeted attacks against unpatched Citrix ADC servers vulnerable to the CVE-2019-19781 exploit.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
It does this by adding the following Windows group policies that disable various protection options in Windows Defender
The fingerprint obtained ... is used to create an event object via CreateEventW with which to check if an instance is already running. This sort of actions is very common in malware to guarantee the execution of a single process, generally with Mutex and Event objects.
If detected, the scripts would attempt to exploit the Windows devices, and if successful, inject a DLL that downloads and installs the Ragnarok ransomware onto the exploited device.
The fingerprint obtained ... is used to create an event object via CreateEventW with which to check if an instance is already running. This sort of actions is very common in malware to guarantee the execution of a single process, generally with Mutex and Event objects.
If detected, the scripts would attempt to exploit the Windows devices, and if successful, inject a DLL that downloads and installs the Ragnarok ransomware onto the exploited device.
The script waited for 60 seconds after it had completed the download, executed the payload, then deleted the static payload data off of storage, a common behavior that attackers employ to remove evidence and complicate the forensic analysis of affected devices.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows ransomware delivered from a compromised firewall to internal Windows hosts. It scans reachable systems, uses EternalBlue and DoublePulsar for propagation/injection, encrypts selected file types, may disable Windows Defender, drops a ransom note, and excludes execution on systems using certain language/localization settings.
Ransomware that attackers attempted to deploy via an unpatched firewall.
Referenced only in a related headline; no substantive discussion in the article body.
Ransomware payload delivered via exploitation of a Sophos XG Firewall zero-day onto companies' Windows systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.