Inactive ransomware operator
← All groupsRagnarlocker
aka Ragnar Locker · 128 victims indexed · first seen 6 years ago · last activity 3 years ago
At a glance
- Status
- inactive
- Aliases
- Ragnar Locker
- First seen
- 6 years ago
- Last activity
- 3 years ago
- Onion sites
- 5 known endpoints
- Primary sector
- Finance · 5 hits
About
References
51 linksExternal sources curated by the MISP threat-intel community.
- bleepingcomputer.com/news/security/ragnar-locker-ransomware-targets-msp-enterprise-support-tools/
- news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/
- cybersecurity-insiders.com/ransomware-attack-makes-cwt-pay-4-5-million-in-bitcoins-to-hackers/
- news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security
- bleepingcomputer.com/news/security/ransomware-gang-threatens-to-leak-data-if-victim-contacts-fbi-police
- twitter.com/malwrhunterteam/status/1475568201673105409
- trellix.com/en-us/about/newsroom/stories/threat-labs/analysis-and-protections-for-ragnarlocker-ransomware.html
- reversing.fun/posts/2021/04/15/unpacking_ragnarlocker_via_emulation.html
- reversing.fun/reversing/2021/04/15/unpacking_ragnarlocker_via_emulation.html
- analyst1.com/blog/ransom-mafia-analysis-of-the-worlds-first-ransomware-cartel
- analyst1.com/file-assets/RANSOM-MAFIA-ANALYSIS-OF-THE-WORLD%E2%80%99S-FIRST-RANSOMWARE-CARTEL.pdf
- blog.blazeinfosec.com/dissecting-ragnar-locker-the-case-of-edp/
- blog.bushidotoken.net/2022/05/gamer-cheater-hacker-spy.html
- blog.cyble.com/2022/01/20/deep-dive-into-ragnar-locker-ransomware-gang/
- blog.reversing.xyz/docs/posts/unpacking_ragnarlocker_via_emulation/
- blog.reversing.xyz/reversing/2021/04/15/unpacking_ragnarlocker_via_emulation.html
- cyware.com/news/ragnar-locker-breached-52-organizations-and-counting-fbi-warns-0588d220/
- docs.google.com/spreadsheets/d/1MI8Z2tBhmqQ5X8Wf_ozv3dVjz5sJOs-3
- go.crowdstrike.com/rs/281-OBQ-266/images/Report2021GTR.pdf
- ics-cert.kaspersky.com/media/KASPERSKY_H1_2020_ICS_REPORT_EN.pdf
Timeline
24 monthsTop countries
Top sectors
MITRE ATT&CK
6 techniques · 5 tacticsTactics
Recent victims
Loading…
Onion infrastructure
5 known- http://p6o7m73ujalhgkiv.onion
- http://ragnarnwvli32xnmwudsvhbl7klzmofxeylyhcqfc5ifx5mbybq3ekqd.onion
- http://rgleak7op734elep.onion
- http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion
- http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/
Source
Updated 3 years agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
