Ragnar is a human-operated ransomware family associated with the broader shift to double-extortion intrusions, in which attackers steal data before encrypting systems and threaten public release to increase pressure on victims. It has been referenced alongside major enterprise-targeting ransomware operations such as REvil, Conti, Maze, DoppelPaymer, CLOP, and Sekhmet, and has been identified as one of the families adopting the leak-site extortion model. Ragnar has been observed in the context of victim data leak tracking and comparative discussions of ransomware encryption performance, indicating its role as an established enterprise-focused ransomware operation during the peak period of big-game hunting campaigns.
High-confidence technical details about Ragnar’s internal implementation, delivery chain, and platform-specific behavior are not available from the supplied facts. The available information supports classifying Ragnar as ransomware and associating it with extortion through leaked-data pressure, but does not support more specific claims about initial access vectors, persistence mechanisms, lateral movement, or operating system targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned in passing as another ransomware family using the same extortion/public shaming model.
Referenced only in a comparative mention alongside other ransomware families.
Mentioned only in comparative statistics of ransomware leak sites.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.