VIKING SPIDER
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
VIKING SPIDER, also known as the Ragnar Locker ransomware group, first emerged in December 2019, quickly establishing itself as a financially motivated threat actor. The group is assessed with high confidence to be of Eastern European origin, specifically from the Commonwealth of Independent States region, a conclusion drawn from the ransomware's built-in functionality to terminate execution if the system's language settings correspond to these geographic areas. Their primary objective is financial extortion, which they pursue through a dual approach of encrypting victim data and threatening to publicly release stolen sensitive information. A defining characteristic that sets VIKING SPIDER apart is its unique defense evasion technique: deploying the Ragnar Locker ransomware payload inside a customized Windows XP virtual machine using Oracle VirtualBox on targeted systems, effectively concealing the malicious activity from host-based security software. The group is also notable for its