The FBI and CISA issued a joint FLASH warning that the Ragnar Locker ransomware gang breached at least 52 organizations across 10 U.S. critical infrastructure sectors, including critical manufacturing, energy, financial services, government, and information technology. The agencies said the group has been active since at least late 2019 and uses double extortion, stealing data before encrypting systems and threatening to publish stolen files on its leak site; stolen data from at least 10 victims had already been posted.
The alert detailed Ragnar Locker tradecraft, including use of VMProtect, UPX, and custom packing, deployment from a custom Windows XP virtual machine, locale checks that halt execution on some CIS-region language settings, termination of services and remote management tools such as ConnectWise and Kaseya, deletion of shadow copies, and selective encryption exclusions. The FBI published indicators including infrastructure, IP addresses, Bitcoin wallets, and operator email addresses tied to access, command-and-control, and exfiltration activity, and urged organizations to report incidents, preserve artifacts, avoid ransom payments, and strengthen defenses with offline backups, MFA, patching, RDP hardening, least-privilege access, and network segmentation.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
On March 7, 2022, the FBI, coordinated with DHS/CISA, issued FLASH CU-000163-MW with updated Ragnar Locker indicators of compromise, technical details, and mitigation guidance.
As of January 2022, the FBI had identified at least 52 entities across 10 U.S. critical infrastructure sectors affected by Ragnar Locker ransomware.
The FBI associated IP address 23.106.122.192 with updt32.exe proxy malware activity on September 27, 2021.
The FBI associated IP address 149.28.200.140 with PSCP activity tied to Ragnar Locker on September 10, 2021.
The FBI associated IP address 185.138.164.18 with access to a Confluence server during a period in September 2021.
The FBI said it first became aware of the Ragnar Locker ransomware threat in April 2020.
Ragnar Locker ransomware payloads were first observed being used in attacks in late December 2019, marking the earliest activity referenced in the sources.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.