Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors VIKING SPIDER

Description

VIKING SPIDER is the criminal group behind the development and distribution of Ragnar Locker ransomware. While public reporting indicates the group began threatening to leak victim data in February 2020, a DLS was not observed until April 2020. The DLS is hosted on Tor, and similar to other actors, proof of data exfiltration is provided before the stolen data is fully leaked. It was also noted that On Dec. 22, 2020, a new post made to MountLocker ransomware’s Tor-hosted DLS was titled 'Cartel News' and included details of a victim of VIKING SPIDER’s Ragnar Locker

AI Analysis

· 1 week ago

Executive Summary

VIKING SPIDER is a sophisticated cybercriminal group known for developing and distributing the Ragnar Locker ransomware. Their primary tactics involve spear-phishing campaigns, data exfiltration, and the use of a dark web data leak site (DLS) to threaten victims with data exposure unless a ransom is paid. They first came into prominence in 2020 and have demonstrated significant operational continuity, targeting sectors and countries where financial gain is prioritized.

Goals & Targeting

VIKING SPIDER's primary goal is financial gain through ransomware attacks and data extortion. They target organizations across multiple sectors, particularly those that handle large volumes of sensitive data. The group's targeting strategy likely focuses on industries with higher recovery costs from downtime or data breaches, such as healthcare providers or financial institutions. Their geographic focus appears to be on regions with active cybercriminal activity and where victims are more likely to pay ransoms, including North America, Europe, and Asia.

Enhanced Description

VIKING SPIDER operates as a cybercriminal group specializing in ransomware activities. The group is notable for its use of the Ragnar Locker ransomware, which it deploys through targeted attacks. VIKING SPIDER's modus operandi involves infecting victim systems, exfiltrating sensitive data, and threatening to release this information unless a ransom is paid. Their attack campaigns often begin with phishing emails that deliver malicious payloads, typically exploiting human error or vulnerabilities in organizational defenses. The group has established a Data Leak Site (DLS) hosted on the Tor network, similar to other advanced cybercriminal groups, where they post evidence of data exfiltration as proof of their ability to harm victims. This tactic increases pressure on companies to negotiate and pay ransoms promptly. VIKING SPIDER's operations have targeted various industries, including healthcare and financial sectors, due to the sensitive nature of the data held by these entities.

Key Capabilities

  • Ransomware distribution via phishing campaigns
  • Data exfiltration and leak site operations
  • Use of Tor infrastructure for command-and-control (C2)
  • Spear-phishing with malicious email attachments
  • Credential dumping and lateral movement within networks

MITRE ATT&CK Tactics

Initial Access
Exfiltration
Defense Evasion
Discovery

ATT&CK Techniques

T1059.003 - Spear-Phishing via Email
T1048 - Exfiltration Over Cryptographic Protocol
T1566.001 - Information Gathering: Data Collection
T1253 - Windows Administrative Shares Access

Software / Tooling

Ragnar Locker Ransomware
MountLocker Ransomware
Custom Phishing Tools
Tor-based C2 Infrastructure

Campaigns & Victims

VIKING SPIDER's campaigns typically involve a phased approach: infection, data exfiltration, and ransom negotiation. Their operations have included high-profile attacks on healthcare facilities, leveraging the sensitive nature of medical data to coerce payments. Notable patterns include the use of DLS as a key component of their extortion strategy and the targeting of organizations with limited incident response capabilities. Campaign data suggests they operate with moderate tempo, balancing persistence with victim impact.

IOC Patterns

  • Spear-phishing emails containing malicious attachments or links
  • Tor-based C2 infrastructure for data leaks
  • Presence of Ragnar Locker ransomware files (e.g., 'VIRUS-*', '~$' appended to filenames)
  • Network traffic indicative of data exfiltration using encrypted channels
  • Scheduled tasks indicating persistence mechanisms

Recommended Actions

  • Implement multi-layered email filtering to detect and block phishing attempts
  • Monitor for unusual network activity, especially encrypted transfers to Tor nodes
  • Conduct regular backups of critical systems and store them offline
  • Enhance user training programs to reduce phishing susceptibility
  • Implement endpoint detection and response (EDR) solutions
  • Harden data exfiltration defenses with network segmentation

Suggested Tags

Ransomware
Cybercrime
Data Leaks
Phishing
Tor Infrastructure

Confidence Assessment

Confidence in this assessment is highbased on publicly available reporting and known TTPs of VIKING SPIDER. However, gaps remain regarding the group's exact geographic origin, internal structure, and long-term strategic goals beyond immediate financial gain.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Data Exfiltration
Cybercrime
Data Leaks
Phishing
Tor Infrastructure

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.