Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how infostealer infections are impacting your business

Ransomware Group : ragnarok

ragnarok


According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.


Ransomware.live has 3 victims in its database for this group.

Victim Name Country Date
FNBNWFL Data leaked 2021-12-30
Decrypt 2021-09-09
Boggi Milano 2021-03-31