Overview

Platforms: Windows
Variants: —
Extensions: —
ATT&CK software: —
Initial access: —
Top countries: —
Observed sectors: —
Tracked victims: 123

Attribution

VIKING SPIDER VERIFIED
Vendor tracking name
CrowdStrike tracks VIKING SPIDER as the criminal group responsible for developing and operating Ragnar Locker ransomware.

Affiliates

No affiliate information available.

Activity

Recent Observations

Ragnar Locker infrastructure seized
October 2023
Law-enforcement action
International law enforcement seized infrastructure supporting Ragnar Locker and took down the operation's Tor data leak site.
FBI reports widespread critical infrastructure impact
March 2022
Critical infrastructure activity
The FBI reported at least 52 organizations across 10 U.S. critical infrastructure sectors affected by Ragnar Locker as of January 2022.
Capcom ransomware attack
November 2020
Major incident
Capcom confirmed a targeted ransomware attack in which affected systems contained a ransom message identifying the attackers as Ragnar Locker.
Maze Cartel collaboration
June 2020
Cybercrime collaboration
VIKING SPIDER joined an apparent collaborative arrangement with Maze operators and LockBit operators involving shared data leak activity.

TTPs

ATT&CK coverage: 5 techniques · 4 tactics
T1059.003 Windows Command Shell
VERIFIED
Execution
Ragnar Locker used cmd.exe and batch scripts to execute commands.
T1543.003 Windows Service
VERIFIED
Persistence / Privilege Escalation
Ragnar Locker used sc.exe to create services associated with its virtualization-based execution technique.
T1569.002 Service Execution
VERIFIED
Execution
Ragnar Locker used Windows services to execute components during ransomware deployment.
Show more TTPs (2)
T1564.006 Run Virtual Instance
VERIFIED
Defense Evasion
Ragnar Locker used VirtualBox and a stripped-down Windows virtual machine to execute ransomware while accessing files on the host through shared folders.
T1486 Data Encrypted for Impact
VERIFIED
Impact
Ragnar Locker encrypted files on local systems and mapped drives before displaying a ransom note.

Victims

Capcom CONFIRMED
November 2020 Japan Media & Entertainment
Media & Entertainment organization in Japan.

CVEs

No CVE associations available.

Infrastructure

Ragnar Locker leak site
Tor-hosted infrastructure was used to publish stolen victim information as part of Ragnar Locker's double-extortion operations.
Operational infrastructure
Backend infrastructure supporting Ragnar Locker operations was seized by law enforcement in the Netherlands, Germany and Sweden.

Timeline

2023-10
International disruption
Law enforcement arrested a key suspect, seized Ragnar Locker infrastructure and took down the operation's Tor data leak site.
2022-01
52 critical infrastructure victims identified
The FBI identified at least 52 organizations across 10 U.S. critical infrastructure sectors affected by Ragnar Locker.
2020-11
Capcom attack
Capcom confirmed a ransomware attack associated with a ransom message from Ragnar Locker.
Show more events (3)
2020-06
Maze Cartel collaboration
VIKING SPIDER entered a documented collaborative arrangement with Maze and LockBit operators involving shared data leak activity.
2020-04
Data leak site observed
VIKING SPIDER began operating a Tor-hosted data leak site to support data-theft extortion.
2019-12
Ragnar Locker first observed
Ragnar Locker ransomware activity was first observed in December 2019.

Sources