Skip to content
Leak site of ragnarlocker, captured by ThreatCluster

ragnarlocker

Inactive

0 tracked victims · First seen Apr 1, 2020 · Last seen Oct 11, 2023

About

Written by ThreatCluster from our own reporting

RagnarLocker is a ransomware group referenced in ThreatCluster's reporting; the material identifies it as a ransomware actor but does not provide detailed extortion model specifics or notable tradecraft. ThreatCluster's victim data records zero victims claimed by RagnarLocker, and the dataset notes that sectors hit most often and countries hit most often are not recorded. A pattern across the recent reporting is that ransomware activity is discussed in the context of exploiting disclosed vulnerabilities; for illustration, the July 15, 2026 SonicWall SMA1000 vulnerabilities under active exploitation demonstrates this dynamic. The February 12, 2026 report notes a global surge in ransomware-driven cyberattacks, averaging about 2,090 per week, providing context for the environment in which RagnarLocker appears in the reporting.

Recent victims

View all →
No recent victims.

All ransomware groups · Dark web intelligence