Description Summary
Ragnar Locker ransomware was active from 2019 to 2023, when its infrastructure was seized in a coordinated international law-enforcement operation led by Europol and the FBI. The group was known for unusual technical choices — running its payload inside a Windows XP virtual machine to evade detection — and for explicitly excluding former-Soviet-state systems from encryption.
Threat Actor
Russian-speaking closed group; one alleged operator was arrested in Paris in October 2023.
Technical Indicators
Encryption Extension
.ragnar_<hash>
Encryption Algorithm
Salsa20 + RSA-2048
Ransom Note Name
RGNR_<hash>.txt
Targeted Industries
Energy, Manufacturing, Travel/hospitality, Critical infrastructure
First Seen
April 2019
Last Seen
October 2023 (infrastructure seizure)
Geographical Location
Europe, North America
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 3 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| T1564.006 | Run Virtual Instance (VirtualBox-based payload) | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |