Netskope Threat Labs

Ragnar Locker

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Ragnar Locker is a ransomware as a service operation active from 2020 until law enforcement seized its infrastructure in 2023, and it targeted companies in critical sectors around the world. Its encryptor ran inside a hidden virtual machine to evade host based security, and its affiliates exfiltrated data before encryption and pressured victims through a leak site. Its takedown, which included the arrest of an alleged developer, showed how international coordination can disrupt established ransomware brands.

First seen
February 2022
Last seen
October 2026
RagnarLockerRagnarlocker

13 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0007 Discovery

  • T1120Peripheral Device Discovery
  • T1614System Location Discovery

TA0040 Impact

  • T1486Data Encrypted for Impact
  • T1489Service Stop
  • T1490Inhibit System Recovery

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
Gen:Variant.Ransom.RagnarLocker.17
Linux.Ransomware.RagnarLocker
Win32.Ransomware.Ragnarlocker
Win32.Ransomware.RagnarLocker