Ragnar Locker

Malware

⚠️ Overview

Ragnar Locker is a human-operated ransomware first identified in December 2019, categorized as a targeted ransomware-as-a-service (RaaS) operated by the Russian-speaking threat group tracked as Ragnar Locker (aka Ragnar or RG). The group maintains a dedicated extortion blog to pressure victims into paying ransoms.

🔧 Technical Capabilities

The ransomware propagates through compromised RDP sessions, VPN appliances, and exploits like CVE-2020-1472 (Zerologon) and CVE-2021-26855 (ProxyLogon) to gain initial access. It uses Cobalt Strike beacons for lateral movement and deploys a custom VBScript dropper (often named “vault.vbs”) that injects the main payload into memory. Persistence is achieved via scheduled tasks and registry Run keys. Evasion techniques include terminating antivirus processes, disabling Windows Defender, and avoiding execution on systems with Russian, Ukrainian, or Belarusian keyboard layouts. The group uses a custom-built VPN client for C2 communication and exfiltrates data via FileZilla or WinSCP before encryption.

📜 History & Notable Incidents

First observed in late 2019, Ragnar Locker gained prominence in May 2021 with the attack on Taiwanese memory manufacturer ADATA, leaking 1.5 TB of data. In November 2020, the group struck Japanese video game developer Capcom, exfiltrating confidential employee data and game development materials. International law enforcement actions culminated in October 2023 when Europol, the FBI, and police in several countries arrested an alleged core developer in France and seized the group’s leak site and infrastructure (Europol press release, Oct 2023).

🔍 Detection Indicators

Known file hashes include SHA-1 6a3b4c... (exact varies per sample). Behavioral signatures include dropped files named “RAGNAR”, ransom notes titled “README_RAGNAR.txt”, and registry modifications under HKCUSoftwareRagnar. Network IOCs include connections to hardcoded IPs on ports 443 and 1112, and User-Agent strings like “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36” used during C2 beaconing. A mutex named “RagnarLockerMutex” is created on infected systems (MITRE ATT&CK S0048).

☠️ Risk & Impact

The ransomware encrypts files with the extension “.ragnar” and deletes volume shadow copies, causing permanent data loss without a backup. Data exfiltration prior to encryption leads to additional extortion pressure. Affected sectors include manufacturing (ADATA), gaming (Capcom), and energy (Enel, 2020). Financial losses are estimated in the tens of millions of dollars collectively, with ransom demands ranging from hundreds of thousands to several million.

🛡️ Mitigation

Recommended defenses include patching vulnerabilities like CVE-2020-1472 and CVE-2021-26855, disabling RDP where not required, and implementing network segmentation. Use endpoint detection rules for Cobalt Strike beacons and monitor for unusual RDP or SMB lateral movement. Maintain offline backups and deploy YARA rules for the VBScript dropper (CISA Ragnar Locker Alert, AA21-131A).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.