Skip to content

ragnarok

Inactive

0 tracked victims · First seen Mar 31, 2021 · Last seen Dec 30, 2021

About

Aggregated threat-intel description

According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.

Recent victims

View all →
No recent victims.

All ransomware groups · Dark web intelligence