Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ragnarlocker

Description

Ragnar Locker was an elite ransomware group active from December 2019 to October 2023 that targeted large enterprises and critical infrastructure — including Capcom and Campari — claiming at least 168 victims before being taken down by a Europol-led international law enforcement operation in October 2023. Known victims: 128 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

RagnarLocker is a sophisticated ransomware group known for its targeted attacks against large enterprises and critical infrastructure, inflicting significant financial harm on victims through encryption-based extortion. Operational between April 2020 and October 2023, the group achieved notoriety by compromising high-profile entities and demanding substantial ransoms. This threat actor was dismantled in a Europol-led international operation in October 2023, marking a significant victory for global law enforcement.

Goals & Targeting

RagnarLocker targeted large enterprises and critical infrastructure sectors, likely selecting victims based on their potential for high financial loss due to data encryption and disruption. The group's focus on high-value targets aligns with its primary motivation of financial gain. Its operational footprint included victims across multiple industries, demonstrating a breadth of targeting that may have been influenced by ease of access or expected ransom payment capacity. RagnarLocker's victims were often geographically dispersed, reflecting the global nature of cybercrime.

Enhanced Description

RagnarLocker emerged as a prominent ransomware group active from April 2020 to October 2023. Specializing in high-value targets such as enterprises and critical infrastructure, the group conducted over 128 successful campaigns before being neutralized by Europol. RagnarLocker's operations were characterized by advanced tactics, techniques, and procedures (TTPs),including spear-phishing, living-off-the-land techniques, and sophisticated malware deployment to infiltrate networks. The group's primary goal was financial gain through the encryption of victims' data, followed by demands for substantial ransoms. Known victims include major companies across industries like entertainment (e.g., Capcom) and food production (e.g., Campari). RagnarLocker's operational persistence from 2020 to 2023 underscores its ability to adapt and evolve in response to victim defenses and law enforcement efforts. The group's takedown highlights the effectiveness of international collaboration in disrupting global cybercriminal networks.

Key Capabilities

  • Custom ransomware development
  • Spear-phishing campaigns
  • Living-off-the-land techniques
  • Network infiltration and lateral movement
  • Encryption-based extortion
  • High-level persistence mechanisms

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Discovery
Lateral Movement

ATT&CK Techniques

T1566.003
T1078.002
T1270.001
T1059.003
T1594.001

Software / Tooling

Custom ransomware (Ragnar Locker)
Mimikatz
Windows Management Instrumentation (WMI)
PowerShell
Covenant Framework
Phishing Tools

Campaigns & Victims

RagnarLocker's campaigns were characterized by a high volume of attacks and a focus on enterprises. The group demonstrated persistence, operational security, and technical proficiency to evade detection. Known victims numbered at least 128 before the takedown, with targeting spanning industries such as entertainment, food production, and others. RagnarLocker's campaigns often employed spear-phishing emails with malicious attachments or links, followed by rapid network infiltration and data encryption. Notable operations include attacks on Capcom and Campari, highlighting its ability to breach critical sectors. The group's operational tempo suggests a focus on maximizing financial gain through efficient attack chains.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • Encrypted communication with C2 servers
  • Use of legitimate tools (e.g., PowerShell, WMI) for malicious activities
  • Ransomware encryption of network shares and critical systems
  • Credential dumping via Mimikatz

Recommended Actions

  • Enhance email filtering to detect phishing attempts.
  • Implement robust backup solutions for critical data.
  • Monitor and restrict the use of living-off-the-land tools in your environment.
  • Conduct regular employee training on identifying phishing emails.
  • Deploy endpoint detection and response (EDR) solutions to catch advanced threats.

Suggested Tags

ransomware
financial-gain
cybercriminal
enterprise-targeted
critical-infrastructure

Confidence Assessment

High confidence in the identification of RagnarLocker as a ransomware group, supported by Europol's announcement of its takedown. Confidence in specific TTPs relies on publicly available reports and known campaign patterns. Limited information is available on the exact tools and techniques used beyond general ransomware behaviors.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
ransomware
financial-gain
cybercriminal
enterprise-targeted
critical-infrastructure

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 1, 2020
Last Seen
Oct 11, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.