VIKING SPIDER is the criminal group behind the development and distribution of Ragnar Locker ransomware. While public reporting indicates the group began threatening to leak victim data in February 2020, a DLS was not observed until April 2020. The DLS is hosted on Tor, and similar to other actors, proof of data exfiltration is provided before the stolen data is fully leaked. It was also noted that On Dec. 22, 2020, a new post made to MountLocker ransomware’s Tor-hosted DLS was titled 'Cartel News' and included details of a victim of VIKING SPIDER’s Ragnar Locker
Executive Summary
VIKING SPIDER is a sophisticated cybercriminal group known for developing and distributing the Ragnar Locker ransomware. Their primary tactics involve spear-phishing campaigns, data exfiltration, and the use of a dark web data leak site (DLS) to threaten victims with data exposure unless a ransom is paid. They first came into prominence in 2020 and have demonstrated significant operational continuity, targeting sectors and countries where financial gain is prioritized.
Goals & Targeting
VIKING SPIDER's primary goal is financial gain through ransomware attacks and data extortion. They target organizations across multiple sectors, particularly those that handle large volumes of sensitive data. The group's targeting strategy likely focuses on industries with higher recovery costs from downtime or data breaches, such as healthcare providers or financial institutions. Their geographic focus appears to be on regions with active cybercriminal activity and where victims are more likely to pay ransoms, including North America, Europe, and Asia.
Enhanced Description
VIKING SPIDER operates as a cybercriminal group specializing in ransomware activities. The group is notable for its use of the Ragnar Locker ransomware, which it deploys through targeted attacks. VIKING SPIDER's modus operandi involves infecting victim systems, exfiltrating sensitive data, and threatening to release this information unless a ransom is paid. Their attack campaigns often begin with phishing emails that deliver malicious payloads, typically exploiting human error or vulnerabilities in organizational defenses. The group has established a Data Leak Site (DLS) hosted on the Tor network, similar to other advanced cybercriminal groups, where they post evidence of data exfiltration as proof of their ability to harm victims. This tactic increases pressure on companies to negotiate and pay ransoms promptly. VIKING SPIDER's operations have targeted various industries, including healthcare and financial sectors, due to the sensitive nature of the data held by these entities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
VIKING SPIDER's campaigns typically involve a phased approach: infection, data exfiltration, and ransom negotiation. Their operations have included high-profile attacks on healthcare facilities, leveraging the sensitive nature of medical data to coerce payments. Notable patterns include the use of DLS as a key component of their extortion strategy and the targeting of organizations with limited incident response capabilities. Campaign data suggests they operate with moderate tempo, balancing persistence with victim impact.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in this assessment is highbased on publicly available reporting and known TTPs of VIKING SPIDER. However, gaps remain regarding the group's exact geographic origin, internal structure, and long-term strategic goals beyond immediate financial gain.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics