Overview
Platforms:
Windows
Variants:
—
Extensions:
—
ATT&CK software:
—
Initial access:
—
Top countries:
—
Observed sectors:
—
Tracked victims:
123
Attribution
VIKING SPIDER
VERIFIED
Vendor tracking name
CrowdStrike tracks VIKING SPIDER as the criminal group responsible for developing and operating Ragnar Locker ransomware.
Affiliates
No affiliate information available.
Activity
Recent Observations
Ragnar Locker infrastructure seized
October 2023
Law-enforcement action
International law enforcement seized infrastructure supporting Ragnar Locker and took down the operation's Tor data leak site.
FBI reports widespread critical infrastructure impact
March 2022
Critical infrastructure activity
The FBI reported at least 52 organizations across 10 U.S. critical infrastructure sectors affected by Ragnar Locker as of January 2022.
Capcom ransomware attack
November 2020
Major incident
Capcom confirmed a targeted ransomware attack in which affected systems contained a ransom message identifying the attackers as Ragnar Locker.
Maze Cartel collaboration
June 2020
Cybercrime collaboration
VIKING SPIDER joined an apparent collaborative arrangement with Maze operators and LockBit operators involving shared data leak activity.
TTPs
ATT&CK coverage:
5 techniques
· 4 tactics
T1059.003
Windows Command Shell
VERIFIEDExecution
Ragnar Locker used cmd.exe and batch scripts to execute commands.
T1543.003
Windows Service
VERIFIEDPersistence / Privilege Escalation
Ragnar Locker used sc.exe to create services associated with its virtualization-based execution technique.
T1569.002
Service Execution
VERIFIEDExecution
Ragnar Locker used Windows services to execute components during ransomware deployment.
Show more TTPs (2)
T1564.006
Run Virtual Instance
VERIFIEDDefense Evasion
Ragnar Locker used VirtualBox and a stripped-down Windows virtual machine to execute ransomware while accessing files on the host through shared folders.
T1486
Data Encrypted for Impact
VERIFIEDImpact
Ragnar Locker encrypted files on local systems and mapped drives before displaying a ransom note.
Victims
Capcom
CONFIRMED
Media & Entertainment organization in Japan.
CVEs
No CVE associations available.
Infrastructure
Ragnar Locker leak site
Tor-hosted infrastructure was used to publish stolen victim information as part of Ragnar Locker's double-extortion operations.
Operational infrastructure
Backend infrastructure supporting Ragnar Locker operations was seized by law enforcement in the Netherlands, Germany and Sweden.
Timeline
2023-10
International disruption
Law enforcement arrested a key suspect, seized Ragnar Locker infrastructure and took down the operation's Tor data leak site.
2022-01
52 critical infrastructure victims identified
The FBI identified at least 52 organizations across 10 U.S. critical infrastructure sectors affected by Ragnar Locker.
2020-11
Capcom attack
Capcom confirmed a ransomware attack associated with a ransom message from Ragnar Locker.
Show more events (3)
2020-06
Maze Cartel collaboration
VIKING SPIDER entered a documented collaborative arrangement with Maze and LockBit operators involving shared data leak activity.
2020-04
Data leak site observed
VIKING SPIDER began operating a Tor-hosted data leak site to support data-theft extortion.
2019-12
Ragnar Locker first observed
Ragnar Locker ransomware activity was first observed in December 2019.