Ransomware Group intelligence
Ragnarlocker
InactiveTrack Ragnarlocker with 128 published victims and 4 known leak locations in a single intelligence view.
Overview
Ragnarlocker is tracked by Breach House as a ransomware group with 128 published victims.
France is currently the most targeted country in this dataset.
4 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (4)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 4 | Onion service | Up checked 2h ago | ragnarnwvli32xnmwudsvhbl7klzmofxeylyhcqfc5ifx5mbybq3ekqd.onion |
| Leak location 2 | Onion service | Up checked 2h ago | rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion |
| Leak location 3 | Onion service | Down checked 2h ago | p6o7m73ujalhgkiv.onion |
| Leak location 1 | Onion service | Down checked 2h ago | rgleak7op734elep.onion |
Top Activity Sectors (16)
- Not identified 48
- Services 35
- Communication / Marketing 8
- Manufacturing / Engineering 7
- Finance / Legal / Insurance 6
- IT 6
- Construction / Real Estate 3
- Telecommunications 3
- Retail / E-commerce 2
- Energy 2
- Transportation / Travel / Logistics 2
- Agriculture / Food 2
- Education 1
- Healthcare / Pharma 1
- Public Sector 1
- Hospitality / Food & Beverage / Tourism 1
Typical Attacks (13)
▼How Ragnarlocker typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Ragnar Locker.
-
T1059.003 Windows Command Shell Execution
What they do: Ragnar Locker has used cmd.exe and batch scripts to execute commands.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1569.002 Service Execution Execution
What they do: Ragnar Locker has used sc.exe to execute a service that it creates.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: Ragnar Locker has used sc.exe to create a new service for the VirtualBox driver.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1218.007 Msiexec Stealth
What they do: Ragnar Locker has been delivered as an unsigned MSI package that was executed with msiexec.exe.
What that means: Adversaries may abuse msiexec.exe to proxy execution of malicious payloads.
-
T1218.010 Regsvr32 Stealth
What they do: Ragnar Locker has used regsvr32.exe to execute components of VirtualBox.
What that means: Adversaries may abuse Regsvr32.exe to proxy execution of malicious code.
-
T1218.011 Rundll32 Stealth
What they do: Ragnar Locker has used rundll32.exe to execute components of VirtualBox.
What that means: Adversaries may abuse rundll32.exe to proxy execution of malicious code.
-
T1564.006 Run Virtual Instance Stealth
What they do: Ragnar Locker has used VirtualBox and a stripped Windows XP virtual machine to run itself.
What that means: Adversaries may carry out malicious operations using a virtual instance to avoid detection.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Ragnar Locker has attempted to terminate/stop processes and services associated with endpoint security products.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1120 Peripheral Device Discovery Discovery
What they do: Ragnar Locker may attempt to connect to removable drives and mapped network drives.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1614 System Location Discovery Discovery
What they do: Before executing malicious code, Ragnar Locker checks the Windows API GetLocaleInfoW and doesn't encrypt files if it finds a former Soviet country.
What that means: Adversaries may gather information in an attempt to calculate the geographical location of a victim host.
-
T1486 Data Encrypted for Impact Impact
What they do: Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Ragnar Locker has attempted to stop services associated with business applications and databases to release the lock on files used by these applications so they may be encrypted.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: Ragnar Locker can delete volume shadow copies using vssadmin delete shadows /all /quiet.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Tools Observed (11)
▼Software Ragnarlocker has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Defense evasion
Discovery & enumeration
LOLBAS (living-off-the-land binaries)
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (4)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
13nmJ3SsNB5pSyQrmX3e6zveY9kHGw8Vs3 |
bitcoin | $4,517,994 | 2 |
19kcqKevFZhiX7NFLa5wAw4JBjWLcpwp3e |
bitcoin | $3,980,534 | 2 |
1CG8RAqNaJCrmEdVLK7mm2mTuuK28dkzCU |
bitcoin | $1,481,197 | 4 |
151Ls8urp6e2D1oXjEQAkvqogSn3TS8pp6 |
bitcoin | $899,289 | 1 |
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (2)
▼The note this group leaves on a compromised machine. Click a filename to read it.
ragnarlocker1.txt
***************************************************************************************************************
HELLO [snip] !
If you reading this message, it means your network was PENETRATED and all of your files and data has been ENCRYPTED
-------------------------------------------------
| |
| by R A G N A R L O C K E R ! |
| |
-------------------------------------------------
***************************************************************************************************************
[ YOU HAVE TO CONTACT US via LIVE CHAT IMMEDIATELY TO RESOLVE THIS CASE AND MAKE A DEAL ]
(contact information you will find at the bottom of this notes)
**** WARNING ****
DO NOT Modify, rename, copy or move any files or you can DAMAGE them and decryption will be impossible.
DO NOT Use any third-party or public Decryption software, it also may DAMAGE files.
DO NOT Shutdown or Reset your system, it can DAMAGE files
---------------------------------------------------------------------
----[WHAT'S HAPPENED]
Your security perimeter was BREACHED and all files on your critically important servers and hosts were completely ENCRYPTED.
Also we has DOWNLOADED about 500GB of your's most SENSITIVE Data just in case if you will NOT PAY, than everything will be PUBLISHED in Media and/or SOLD to any third-party.
We have collected the most important info such as:
-Accounting files, Financial Reports, Banking and Billing statements, HR documents, Payrolls, AFIP/ASIF databases
-Logistics Files, SQL Databases, ID cards, DL's, Transport Documents, Certificates of Transport Ministry, Phonebooks
-Confidential Agreements, Corporate Contracts, WorkFiles, Clients Information, License Keys, Surveillance cameras video
-Also we have your Private emails in .msg and .pst files and a lot of other Sensitive info.
----[WHAT SHOULD YOU DO]
- You have to contact us as soon as possible(you can find contacts below), we are offering discounts for quick deals so price can be better if you will respect our time.
- You should purchase our decryption tool, so will be able to restore your files. Without our Decryption keys it's impossible.
- You should make a Deal with us, to avoid your Data leakage.
- You should stay away from any third-parties recovery soft, since it could damage files.
- You should avoid any scammers using our name in different communication ways. We communicate only via LIVE CHAT
----[YOUR OPTIONS]
#1 If NO contact or Deal made in 3(three) Days than all your Data will be Published and/or Sold to any third-parties, Decryption key will be deleted permanently and recovery will be impossible.
Also this would be disastrous consequences to your's business reputation.
#2 If we make a Deal:
We will provide you with the Decryption Key and Manual how-to-use.
We will remove all your files from our file-storage with proof of Deletion and delete posts regarding your company with Guarantee to avoid any Data Leaks to public or to any third-parties.
Also we will help you to improve the security measures and provide you with the technical report and list of security-recommendations.
----
[There are couple of screenshots just as a proofs of data possession, you can find more in our Leak Blog]
Screenshots:
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
---------------------------------------------------------------------
Leak Blog Access:
This temporary post stays hidden only during 4(four) days until we make a Deal. Later, if we don't make a Deal it would be supplemented and become permanent and accessible for everyone.
Leak Blog: http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?[snip]
Password: [snip]
(use Tor Browser to open the link)
======================================================================
[ HERE IS THE SIMPLE MANUAL HOW TO GET CONTACT WITH US VIA LIVE CHAT ]
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
a) Download and install TOR browser from this site : https://torproject.org
b) For contact us via LIVE CHAT open our website : http://ragnarjtm25k3w4cy6kvfttfhm24mpynikjt7yll5pvpfo4a7yuzweyd.onion/client/?[snip]
c) To visit TEMPORARY LEAK PAGE with your data on our News Blog, open this website: http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?[snip]
password: [snip]
d) If Tor is restricted in your area, use VPN
e) All your Data will be published in 4(four) Days if NO contact made
f) Your Decryption keys will be permanently destroyed in 4(four) Days if no contact made
When you open LIVE CHAT website follow rules :
Follow the instructions on the website.
At the top you will find CHAT tab.
Send message to us and wait for response (we are not online 24/7, So you have to wait for your turn).
*We advise you to find some information about us in google and also check the tab "About Us" in our Blog (http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?about-us)
***********************************************************************************
---A PRIVATE KEY---
[snip]
---Z PRIVATE KEY---
***********************************************************************************
!_^_README_NOTES_RAGNAR_^_!.txt
********************************************************************************************************************
HELLO [snip] !
If you reading this message, it means your network was PENETRATED and your most sensitive files were COMPROMISED
-------------------------------------------------
| |
| by R A G N A R L O C K E R ! |
| |
-------------------------------------------------
********************************************************************************************************************
[ YOU HAVE TO CONTACT US via LIVE CHAT IMMEDIATELY TO RESOLVE THIS CASE AND MAKE A DEAL ]
(contact information you will find at the bottom of this notes)
**** WARNING ****
DO NOT Hire any third-party negotiators (recovery/FBI/police and etc), otherwise we will close chat immediately and Publish your Data.
---------------------------------------------------------------------------------------------------------------------------------------
----[WHAT'S HAPPENED]
With this message we want to let you know that we has obtained access everywhere in your network and we was able to encrypt your files and servers.
However, we didn't do that only because of willing to avoid interruption in hospitals normal business processes and don't put health of the patients under risk.
But unfortunately, you has allowed data leak, about 1TB of personal data was compromised. So, your clients didn't get the required protection.
Tottally we has DOWNLOADED about 1TB of your CONFIDENTIAL and most SENSITIVE Data just in case if you will NOT PAY, if so, than everything will be PUBLISHED in Media and/or SOLD to any third-party.
WE HAS COLLECTED SUCH DATA AS:
- Medical record, medical history, Information regarding diagnoses and surgeries
- Clients personal info: Relatives/Address/DOB/email/phones and etc., Private letters and correspondence
- Departments: Oncology, Pediatrics, Surgery, Urology, Oculist, Cardiology, Gynecology and others
- Financial reports, Revenue, Budgets, Payrolls, Expenses, Bank statements
- Databases, Credentials, access to emails and accounts, Passwords, Workfiles
- And many other sensitive data...
----[WHAT SHOULD YOU DO]
- You have to contact us as soon as possible (you can find contacts below)
- You should make a Deal with us, to avoid LEAK of your Sensitive Data
- You should avoid any scammers using our name in different communication ways. We communicate only via LIVE CHAT
- You should avoid any third-party negotiators and recovery groups
----[YOUR OPTIONS]
1) IF NO CONTACT OR DEAL MADE IN 3 DAYS:
All your Data will be Published and/or Sold to any third-parties
Information regarding vulnerabilities of your network also can be published and/or sold
Such Leakage will have disastrous consequences to your business reputation.
2) If WE MAKE A DEAL:
We will remove all your files from our file-storage with proof of Deletion
We will permanently delete post with your company name
We guarantee to avoid sharing any details with third-parties
We will provide you with the penetration report and list of security-recommendations
[Here are couple of screenshots just as a proofs of Data possession, you can find more in our Leak Blog]
Screenshots:
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
https://prnt.sc/[snip]
-------------------------------------------------------------------------------------------------------------
LEAK BLOG ACCESS:
This temporary post stays hidden only during 3(three) days until we make a Deal.
If the Deal not made, Post would be supplemented and become permanent and accessible for everyone!
LEAK BLOG: http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?[snip]
Password: [snip]
(use Tor Browser to open the link)
======================================================================
[ HERE IS THE SIMPLE MANUAL HOW TO GET CONTACT WITH US VIA LIVE CHAT ]
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
1) Download and install TOR browser from this site : https://torproject.org
2) For contact us via LIVE CHAT open our website : http://ragnarmj3hlykxstyanwtgf33eyacccleg45ctygkuw7dkgysict6xyd.onion/client/?[snip]
3) To visit TEMPORARY LEAK PAGE with your data on our Leaks Blog
open this website: http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?[snip]
password: [snip]
4) If Tor is restricted in your area, use VPN
5) All your Data will be published in 3(three) Days if NO contact made
6) Information regarding vulnerabilities in your network will be Sold or Published
7) Your Data will be published if you will hire third-party negotiators to contact us
*We advise you to find some information about us in google
Also check the tab "About Us" in our Blog (http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/?about-us)
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (128)
Search, filter and paginate the victim timeline for Ragnarlocker. Showing 101–128 of 128.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | LEAK Post Campari Group id541 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Updates with files in EastCoastSeafood Inc. id542 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New "WallofShamer" - East Coast Seafood Inc. id543 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Shasun Chemicals & Drugs Ltd. LEAK id539 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | JMA Energy LEAK id538 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New Files For Leak Campari Post id532 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ragnar_Team Announce of Potential "WallofShamer" id522 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | LEAK Post CAPCOM id520 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | LEAK post FINSA id521 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Campari Group id514 View details | Italy | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Official appeal to DASSAULT FALCON JET id517 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DASSAULT FALCON JET id513 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Security breach of CAPCOM network id504 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Security breach of Campari Group network id494 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CMA CGM (french carrier, container line) id485 View details | France | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | BIOLOGICAL E. Ltd. (BE) LEAK POST id484 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Insignia Environmental company. id442 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Astro Industries, Inc. id423 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Bailey&Galyen Attorney at Law id424 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | New leaks from SOLTEK PACIFIC id425 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GST Autoleather Company ! id426 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ST Engineering id427 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Leaks from company EDP Group id420 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Leaks from company Omniga GmbH & Co. id421 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Leakage from company Catania, Mahon & Rider, PLLC id418 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Brunner Announce – Hello World ! id419 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Leaks Company Birch Communications inc. id416 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Energias de Portugal (EDP) id349 View details | Portugal | Other | — | |
|
No additional victim description available. |
|||||