ragnarok
First seen March 31, 2021Active3 claimed victims
The claims below are reproduced as posted by ragnarok on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.
Listed organisation? Contact [email protected].
Profile
According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.
Description from ransomware.live.
Claimed victims (as posted by the group — unverified)
| Victim (as posted) | Claimed on | Source | Press coverage |
|---|---|---|---|
| FNBNWFL Data leaked | December 30, 2021 | ransomware_live | — |
| Decrypt | September 9, 2021 | ransomware_live | — |
| Boggi Milano | March 31, 2021 | ransomware_live | — |
Claim data from ransomware.live and RansomLook (CC BY 4.0).