Uptime Hamster: 12d 19h 58mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza ragnarok

ragnarok

2 incidentes 2 paises 0 sectores ransomware CN Ultimo: 2026-06-29
Aliases: Ragnar Locker, Asnarök, Asnarok
Ver en IntelTracker → APTTrail →
Ragnarok is a ransomware group that emerged in late 2019, quickly establishing itself by targeting corporate networks with its ransomware variant. The group is primarily motivated by financial gain, employing a double extortion model where they encrypt data and threaten to leak stolen sensitive information if a ransom is not paid. Ragnarok distinguished itself by its early adoption of distributing malware via ISO files and notably deployed its ransomware inside a virtual machine to evade detection, a unique operational approach at the time. A month before its eventual shutdown, the group rebranded as 'Daytona by Ragnarok', with operations concluding and a universal decryption key released in August 2021. The group is assessed with high confidence to be of Russian or Commonwealth of Independent States (CIS) origin, evidenced by its ransomware terminating execution on systems configured with specific language IDs, including those corresponding to Russia, Belarus, Ukraine, and China.

Aliases del actor

Ragnar LockerAsnarökAsnarok

Actores similares

ragnarlockerransomware · 2Ragnar Lockerransomware · 0medusalockeractor · 26tridentlockerransomware · 6avoslockerransomware · 3chilelockerransomware · 3alphalockeractor · 3GDLockerSecransomware · 2adminlockerransomware · 2bluelockerransomware · 2

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownsushlnty2j7qdzy64qnvyb6ajkwg7resd3p6agc2widnawodtcedgjid.onionragnarok
DLS / leak siteupransomware.anggipradana.comRansomware Group: ragnarok
Tecnicas MITRE
TA0011, TA0008, TA0040, TA0043, TA0007
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

China (1) Russia (1)

Paises objetivo (SOCRadar)

AustraliaBangladeshBelgiumSwitzerlandCzech RepublicGermanyEstoniaSpainFranceUnited Kingdom

Sectores objetivo (SOCRadar)

Food ManufacturingOther Information ServicesRail TransportationSoftware PublishersAir TransportationManufacturingElectrical Equipment, Appliance, and Component ManufacturingPublic AdministrationOil & GasBeverag & Tobacco Manufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com