Description Summary
According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.
Threat Actor
Closed group; exploited unpatched Citrix ADC (CVE-2019-19781); excluded Russian/Chinese systems.
Technical Indicators
Encryption Extension
.ragnarok / .thor / .[random]
Encryption Algorithm
AES (dynamic key) + RSA (key wrapping)
Ransom Note Name
!!Read_me!!.txt / How_To_Decrypt_My_Files.txt
Targeted Industries
Cross-sector
First Seen
Late 2019
Last Seen
August 2021 (shut down; released master decryption key)
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |