Also known as: Vikingdom
Executive Summary
Viking Jackal, also known as Vikingdom, is suspected to be an advanced persistent threat (APT) group targeting financial institutions globally. The group likely employs sophisticated tactics such as spear phishing, credential harvesting, and ransomware deployment. Their operations suggest a focus on high-value assets and data theft for potential financial gain or espionage.
Goals & Targeting
Viking Jackal's strategic objectives likely center on financial gain through ransomware campaigns and potential espionage activities targeting sensitive sector information. Their targeting of financial institutions suggests a focus on high-value assets and the disruption of critical services. The group appears to prioritize English-speaking countries, possibly due to weaker organizational security frameworks or easier access vectors.
Enhanced Description
Viking Jackal is a cyber威胁组织 that has demonstrated advanced operational capabilities through attacks attributed to the RagnarLocker ransomware family. The group appears to target financial institutions, government entities, and critical infrastructure sectors. Their tactics include phishing campaigns, watering hole attacks, and the use of legitimate tools such as remote administration software for malicious purposes. The actors are known for their ability to maintain long-term persistence within victim networks, allowing them to exfiltrate sensitive data or deploy destructive payloads.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Viking Jackal has been linked to multiple attacks targeting financial institutions across Europe and North America. Their campaigns often involve a phased approach, starting with spear-phishing emails containing malicious macros or legitimate-looking files. Once inside the network, the actors establish persistence and move laterally to identify high-value assets before deploying ransomware or exfiltrating data. Notable campaigns include those involving the RagnarLocker variant that includes a kill-switch mechanism tied to specific domains.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the association between Viking Jackal and RagnarLocker due to linked IOCs. Additional details on TTPs and campaign history could enhance understanding of this actor's true capabilities and objectives.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics