Ragnar Loader, also known as Sardonic and sometimes referred to by operators as the Ragnar Framework, is a malware toolkit associated with the Ragnar Locker ransomware ecosystem, also tracked as Monstrous Mantis. It has been used since at least 2020 in targeted intrusions to establish and maintain persistent access on compromised systems, support the initial breach phase, and prepare victim environments for broader network takeover and ransomware operations. Reporting also notes its use by other financially motivated intrusion clusters including FIN7 and FIN8.
The malware’s primary role is to provide durable footholds in victim networks and enable follow-on activity by operators. High-confidence reporting links it to persistent access and long-term retention within compromised environments, making it a key enabler for post-compromise control and subsequent ransomware deployment. Its use within affiliate-driven operations indicates it functions as part of a broader intrusion framework rather than as a standalone destructive payload.
Ragnar Loader is associated with targeted attacks against organizations rather than indiscriminate mass distribution. The available facts support its role in intrusion enablement, persistence, and operational staging for ransomware actors, but do not provide sufficient high-confidence detail here on specific victim sectors, technical internals, or a definitive delivery vector.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ragnar Loader, also known as Sardonic, is a sophisticated toolkit of the Monstrous Mantis (a.k.a. Ragnar Locker) ransomware group... Ragnar Loader often referred to as the Ragnar Framework by its affiliates—plays an essential role by establishing persistent access to compromised systems and ensuring long-term fixation.
FIN7, FIN8, and Others Use Ragnar Loader for Persistent Access and Ransomware Operations
FIN7, FIN8, and Others Use Ragnar Loader for Persistent Access and Ransomware Operations
FIN7, FIN8, and Others Use Ragnar Loader for Persistent Access and Ransomware Operations
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware toolkit used for persistent access and to support long-term operations; used by multiple cybercrime/ransomware groups and associated with ransomware operations.
Loader/tooling referenced as part of the actor’s C2/post-compromise stack.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.