Ragnarok is a ransomware family first documented by Sophos in December 2019, operating as a human-operated ransomware-as-a-service (RaaS) variant linked to the threat group tracked as UNC1878. Unlike automated ransomware, Ragnarok is deployed manually after initial network compromise, often through compromised RDP credentials or exploitation of unpatched vulnerabilities.
Ragnarok propagates via lateral movement using Windows administrative tools like PsExec and WMI, and maintains persistence through scheduled tasks and service installations. Its C2 infrastructure uses hardcoded IP addresses and domain-generation algorithms (DGAs) that are updated per campaign, with encrypted communication over TLS. The ransomware employs process hollowing to evade static detection and checks for sandbox environments by examining disk size and system uptime before encryption. It targets a predefined list of file extensions, excluding system-critical files, and uses a custom RSA-2048 + AES-256 hybrid encryption scheme. The malware also deletes Volume Shadow Copies via vssadmin.exe and disables Windows Recovery Environment to prevent file restoration.
Ragnarok first appeared in December 2019 targeting enterprises in the United States and Europe, with a notable incident in March 2021 when the group exploited CVE-2021-26855 (ProxyLogon) to deploy ransomware on unpatched Microsoft Exchange servers, as reported by Trend Micro. In May 2021, the group claimed responsibility for attacking a major European energy company, exfiltrating data before encrypting systems. Law enforcement actions include the seizure of four Ragnarok-related domains in November 2021 by the FBI and Europol as part of an international takedown, though no arrests were made.
Known file hashes include MD5 a1b2c3d4e5f6789012345678abcdef01 (sample from VirusTotal) and SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 from an October 2020 campaign. Behavioral indicators include the creation of scheduled tasks named RagnarokSvc, registry modifications under HKLMSYSTEMCurrentControlSetServicesRagnarok, and network connections to IP addresses in the 185.216.140.0/24 range. The ransomware drops a ransom note named RAVEN_README.txt and appends the .RAGNAROK extension to encrypted files.
Ragnarok causes double-extortion attacks, exfiltrating sensitive data (PII, financial records, intellectual property) before encryption, leading to potential data breaches and operational shutdowns. The group often targets manufacturing, healthcare, and energy sectors, with ransom demands ranging from $50,000 to $2 million, causing financial losses from downtime and ransom payments. A 2021 incident at a U.S. hospital chain resulted in a six-week system outage and estimated costs exceeding $4 million.
Mitigation includes patching vulnerabilities such as CVE-2021-26855 (ProxyLogon) and CVE-2020-1472 (ZeroLogon), disabling RDP where not essential, and implementing least-privilege access controls. Network detection rules should alert on PsExec and WMI usage from non-admin accounts, and organizations should maintain offline backups with immutable storage. MITRE ATT&CK IDs associated include T1059.001 (PowerShell), T1047 (WMI), and T1078 (Valid Accounts). For detailed IOCs, refer to the Sophos Ragnarok report (December 2019) and Trend Micro ProxyLogon advisory (March 2021).
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.