HackerFeeds
All ransomware groups

ragnarok

3 tracked victims
·first seen 2021-03-31·last activity 2021-12-30

Group profile

According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.

Recent victims

DateWebsite / victimSectorCountry
2021-12-30
F
FNBNWFL Data leaked
Financial Services
2021-09-09
D
Decrypt
Technology
2021-03-31
B
Boggi Milano
Consumer Services