Description
Ragnar Locker is a ransomware as a service operation active from 2020 until law enforcement seized its infrastructure in 2023, and it targeted companies in critical sectors around the world. Its encryptor ran inside a hidden virtual machine to evade host based security, and its affiliates exfiltrated data before encryption and pressured victims through a leak site. Its takedown, which included the arrest of an alleged developer, showed how international coordination can disrupt established ransomware brands.
Stats
- First seen
- February 2022
- Last seen
- October 2026
Also known as
RagnarLockerRagnarlocker
MITRE ATT&CK techniques
13 techniques across 6 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.RagnarLocker.17 |
| Linux.Ransomware.RagnarLocker |
| Win32.Ransomware.Ragnarlocker |
| Win32.Ransomware.RagnarLocker |