Ragnar Locker Ransomware

Description Summary

Ragnar Locker ransomware was active from 2019 to 2023, when its infrastructure was seized in a coordinated international law-enforcement operation led by Europol and the FBI. The group was known for unusual technical choices — running its payload inside a Windows XP virtual machine to evade detection — and for explicitly excluding former-Soviet-state systems from encryption.

Threat Actor

Russian-speaking closed group; one alleged operator was arrested in Paris in October 2023.

Technical Indicators

Encryption Extension
.ragnar_<hash>
Encryption Algorithm
Salsa20 + RSA-2048
Ransom Note Name
RGNR_<hash>.txt
Targeted Industries
Energy, Manufacturing, Travel/hospitality, Critical infrastructure
First Seen
April 2019
Last Seen
October 2023 (infrastructure seizure)
Geographical Location
Europe, North America

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 3 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
T1564.006 Run Virtual Instance (VirtualBox-based payload)
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop