← Back to all threat actors

ragnarok

According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.

How we source and review actor profiles
Motivation
ransomware
Last seen
2021-12-30
Sectors
financial-services, technology, retail-e-commerce
Status
Dormant

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

First listed
Victim claimFNBNWFL Data leaked listed by ragnarok

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Last observed
Indicator2 indicators cataloged

Types: onion.

First listed
Victim claimDecrypt listed by ragnarok

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed
Claimed
Victim claimBoggi Milano listed by ragnarok

Actor-claimed victim evidence. This listing is not independent confirmation of compromise.

Actor Claimed

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

ragnarokCanonical Name

Loading CVEs, techniques, indicators, malware, victims, and activity...