VIKING SPIDER is an eCrime threat actor associated with operation of the Ragnar Locker ransomware. The group has been linked to big-game hunting intrusions and has also been described as collaborating with other ransomware operators in the Maze Cartel, including TWISTED SPIDER and LockBit-associated actors. Ragnar Locker is the malware family most closely associated with this actor. VIKING SPIDER uses varied initial access methods. Reported intrusion paths include direct exploitation of exposed systems, abuse of legitimate applications, and implantation of malware within legitimate software. The actor’s operations are consistent with enterprise-wide ransomware tradecraft aimed at obtaining broad access and control inside victim environments before encryption is launched. Ragnar Locker behavior associated with VIKING SPIDER includes victim-environment profiling, locale-based execution filtering, service enumeration, and selective encryption. The malware checks system locale early in execution and terminates on systems matching an internal exclusion list dominated by CIS-region languages. It gathers host and operating-system identifiers, enumerates services, and identifies processes and services associated with backup, security, and remote-management tooling. It then creates a ransom note with a victim identifier and launches that note in the active user session. Encryption avoids selected folders, files, and extensions and appends actor-specific marker data to encrypted files. The actor’s observed tradecraft supports a financially motivated ransomware-and-extortion model centered on encryption and victim negotiation. VIKING SPIDER is also noted in public reporting alongside other major ransomware actors that announced an intention to avoid targeting frontline healthcare entities, although such statements should not be treated as a reliable operational constraint.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with RagnarLocker ransomware operations, using varied initial access methods, direct exploitation, abuse of legitimate applications, malware implantation, privilege/access expansion inside victim environments, and broad file encryption across enterprise systems.
Listed as part of a broader 'Ransom Cartel/Maze Cartel' collection of criminals (per cited reporting) that use ransomware for extortion; no further specifics in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.