Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Viking Jackal

Also known as: Vikingdom

AI Analysis

· 1 week ago

Executive Summary

Viking Jackal, also known as Vikingdom, is suspected to be an advanced persistent threat (APT) group targeting financial institutions globally. The group likely employs sophisticated tactics such as spear phishing, credential harvesting, and ransomware deployment. Their operations suggest a focus on high-value assets and data theft for potential financial gain or espionage.

Goals & Targeting

Viking Jackal's strategic objectives likely center on financial gain through ransomware campaigns and potential espionage activities targeting sensitive sector information. Their targeting of financial institutions suggests a focus on high-value assets and the disruption of critical services. The group appears to prioritize English-speaking countries, possibly due to weaker organizational security frameworks or easier access vectors.

Enhanced Description

Viking Jackal is a cyber威胁组织 that has demonstrated advanced operational capabilities through attacks attributed to the RagnarLocker ransomware family. The group appears to target financial institutions, government entities, and critical infrastructure sectors. Their tactics include phishing campaigns, watering hole attacks, and the use of legitimate tools such as remote administration software for malicious purposes. The actors are known for their ability to maintain long-term persistence within victim networks, allowing them to exfiltrate sensitive data or deploy destructive payloads.

Key Capabilities

  • Ransomware deployment (RagnarLocker)
  • Spear phishing campaigns
  • Watering hole attacks
  • Legitimate tool abuse (e.g., Radmin RAT)
  • Credential harvesting and lateral movement within networks

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Defense Evasion
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059
T1047
T1055
T1003
T1566

Software / Tooling

RagnarLocker ransomware
Cobalt Strike (suspected)
Mimikatz (credential dumping tool)
Custom backdoors
Radmin remote administration tool

Campaigns & Victims

Viking Jackal has been linked to multiple attacks targeting financial institutions across Europe and North America. Their campaigns often involve a phased approach, starting with spear-phishing emails containing malicious macros or legitimate-looking files. Once inside the network, the actors establish persistence and move laterally to identify high-value assets before deploying ransomware or exfiltrating data. Notable campaigns include those involving the RagnarLocker variant that includes a kill-switch mechanism tied to specific domains.

IOC Patterns

  • Spear-phishing emails with malicious macros
  • Legitimate-looking files (e.g., DLLs) hosting malicious code
  • C2 communications using HTTPS or legitimate services
  • Ransomware encryption patterns consistent with RagnarLocker

Recommended Actions

  • Implement advanced email filtering to detect spear phishing attempts.
  • Monitor for unusual network activity, particularly related to known C2 domains.
  • Conduct regular backups of critical systems and ensure they are offline from the network.
  • Train employees to recognize suspicious emails and attachments.
  • Patch all systems regularly to mitigate potential exploitation vectors.

Suggested Tags

APT
ransomware
financial-sector
espionage
persistent-threat

Confidence Assessment

Moderate confidence in the association between Viking Jackal and RagnarLocker due to linked IOCs. Additional details on TTPs and campaign history could enhance understanding of this actor's true capabilities and objectives.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
ransomware
financial-sector
espionage
persistent-threat

Details

Type
Unknown
Country of Origin
A
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.