Uptime Hamster: 10d 6h 40mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza VIKING SPIDER

VIKING SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
VIKING SPIDER, also known as the Ragnar Locker ransomware group, first emerged in December 2019, quickly establishing itself as a financially motivated threat actor. The group is assessed with high confidence to be of Eastern European origin, specifically from the Commonwealth of Independent States region, a conclusion drawn from the ransomware's built-in functionality to terminate execution if the system's language settings correspond to these geographic areas. Their primary objective is financial extortion, which they pursue through a dual approach of encrypting victim data and threatening to publicly release stolen sensitive information. A defining characteristic that sets VIKING SPIDER apart is its unique defense evasion technique: deploying the Ragnar Locker ransomware payload inside a customized Windows XP virtual machine using Oracle VirtualBox on targeted systems, effectively concealing the malicious activity from host-based security software. The group is also notable for its

Actores similares

Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1
Motivacion