Ragnar Locker was an elite ransomware group active from December 2019 to October 2023 that targeted large enterprises and critical infrastructure — including Capcom and Campari — claiming at least 168 victims before being taken down by a Europol-led international law enforcement operation in October 2023. Known victims: 128 2 ransom note(s) on file
Objectives
Executive Summary
RagnarLocker is a sophisticated ransomware group known for its targeted attacks against large enterprises and critical infrastructure, inflicting significant financial harm on victims through encryption-based extortion. Operational between April 2020 and October 2023, the group achieved notoriety by compromising high-profile entities and demanding substantial ransoms. This threat actor was dismantled in a Europol-led international operation in October 2023, marking a significant victory for global law enforcement.
Goals & Targeting
RagnarLocker targeted large enterprises and critical infrastructure sectors, likely selecting victims based on their potential for high financial loss due to data encryption and disruption. The group's focus on high-value targets aligns with its primary motivation of financial gain. Its operational footprint included victims across multiple industries, demonstrating a breadth of targeting that may have been influenced by ease of access or expected ransom payment capacity. RagnarLocker's victims were often geographically dispersed, reflecting the global nature of cybercrime.
Enhanced Description
RagnarLocker emerged as a prominent ransomware group active from April 2020 to October 2023. Specializing in high-value targets such as enterprises and critical infrastructure, the group conducted over 128 successful campaigns before being neutralized by Europol. RagnarLocker's operations were characterized by advanced tactics, techniques, and procedures (TTPs),including spear-phishing, living-off-the-land techniques, and sophisticated malware deployment to infiltrate networks. The group's primary goal was financial gain through the encryption of victims' data, followed by demands for substantial ransoms. Known victims include major companies across industries like entertainment (e.g., Capcom) and food production (e.g., Campari). RagnarLocker's operational persistence from 2020 to 2023 underscores its ability to adapt and evolve in response to victim defenses and law enforcement efforts. The group's takedown highlights the effectiveness of international collaboration in disrupting global cybercriminal networks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RagnarLocker's campaigns were characterized by a high volume of attacks and a focus on enterprises. The group demonstrated persistence, operational security, and technical proficiency to evade detection. Known victims numbered at least 128 before the takedown, with targeting spanning industries such as entertainment, food production, and others. RagnarLocker's campaigns often employed spear-phishing emails with malicious attachments or links, followed by rapid network infiltration and data encryption. Notable operations include attacks on Capcom and Campari, highlighting its ability to breach critical sectors. The group's operational tempo suggests a focus on maximizing financial gain through efficient attack chains.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the identification of RagnarLocker as a ransomware group, supported by Europol's announcement of its takedown. Confidence in specific TTPs relies on publicly available reports and known campaign patterns. Limited information is available on the exact tools and techniques used beyond general ransomware behaviors.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics