Ragnar Locker, also known as RagnarLocker, Ragnar_Locker, Ragnar_Locker_Group, and Ragnar_Locker_Team, is a financially motivated cybercriminal ransomware and extortion operation first observed in late 2019. It primarily targeted large enterprises and critical infrastructure organizations, particularly in the United States. By January 2022, at least 52 U.S. organizations across 10 critical infrastructure sectors had been affected, including manufacturing, energy, financial services, government, and information technology. Notable victims include Energias de Portugal, Capcom, Campari Group, and Israel’s Mayanei Hayeshua hospital. The group conducts targeted intrusions, steals sensitive information, and deploys victim-specific Windows ransomware. Initial access methods include abuse of exposed Remote Desktop Protocol services and exploitation involving managed service providers. Operators have used PowerShell and Group Policy for lateral movement and ransomware deployment after obtaining domain administrator access. A distinctive defense-evasion technique runs ransomware inside an Oracle VirtualBox Windows XP guest, encrypting host and network drives exposed through shared folders. The malware employs packing and anti-debugging measures, terminates security, backup, and remote-management services, deletes shadow copies, and disables recovery features. It uses Salsa20-based encryption with RSA protection for encryption keys and avoids execution under several former Soviet-region language settings. Ragnar Locker combines encryption with threats to publish stolen information on a public leak site and has also used encryption-less data-theft extortion. It adopted DDoS-assisted triple extortion in 2020 and used fraudulent Facebook advertisements to pressure Campari into payment. The operation participated in the loose Maze Cartel alongside Maze and LockBit, including cooperation in publishing stolen data; these groups are not aliases or subgroups of Ragnar Locker. In October 2023, an international law enforcement operation seized its leak portal and infrastructure and arrested an alleged principal operator in Paris, with related investigative actions in the Czech Republic and Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operators conducting big-game extortion against large companies and business users, encrypting files and stealing data beforehand for leak-based pressure, with additional use of DDoS coercion. The content also describes their use of a VirtualBox Windows XP VM to evade host-based antivirus during encryption.
Mentioned only as a previously linked Russia-aligned threat actor in background context about RansomHouse.
Conducted a ransomware attack against TAP Air Portugal and later leaked compromised data on a public dark web site.
Ransomware activity associated with the WIN-344VU98D3RU ISPsystem-derived hostname.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.