ragnarok logo

ragnarok

1 incidentes 1 paises 0 sectores ransomware CN Ultimo: 2026-06-25
Aliases: Ragnar Locker, Asnarök, Asnarok
Ver en IntelTracker → APTTrail →
Ragnarok is a ransomware group that emerged in late 2019, quickly establishing itself by targeting corporate networks with its ransomware variant. The group is primarily motivated by financial gain, employing a double extortion model where they encrypt data and threaten to leak stolen sensitive information if a ransom is not paid. Ragnarok distinguished itself by its early adoption of distributing malware via ISO files and notably deployed its ransomware inside a virtual machine to evade detection, a unique operational approach at the time. A month before its eventual shutdown, the group rebranded as 'Daytona by Ragnarok', with operations concluding and a universal decryption key released in August 2021. The group is assessed with high confidence to be of Russian or Commonwealth of Independent States (CIS) origin, evidenced by its ransomware terminating execution on systems configured with specific language IDs, including those corresponding to Russia, Belarus, Ukraine, and China.
Tecnicas MITRE
TA0011, TA0008, TA0040, TA0043, TA0007

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

Russia (1)

Paises objetivo (SOCRadar)

AustraliaBangladeshBelgiumSwitzerlandCzech RepublicGermanyEstoniaSpainFranceUnited Kingdom

Sectores objetivo (SOCRadar)

Food ManufacturingOther Information ServicesRail TransportationSoftware PublishersAir TransportationManufacturingElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationOil & GasBeverag & Tobacco Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com