RagnarLocker (ELF)
- First seen
- 2019-12-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:47:20
Targeted industries: energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing retail-and-hospitality
Context
RagnarLocker is a ransomware family known for encrypting files on systems and demanding a ransom for decryption keys. It employs a unique technique of deploying the ransomware as a virtual machine in order to evade detection by security software. RagnarLocker is often associated with double extortion tactics, threatening to release stolen data if the ransom is not paid.
Reports & references
- twitter.com — 1475568201673105409 (report)
- trellix.com — Analysis And Protections For Ragnarlocker Ransomware (report)
- noticeofpleadings.com — 1%20 Microsoft%20Cobalt%20Strike%20 %20Complaint(907040021.9) (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Ragnarlocker (report)
- techcrunch.com — Ragnarlocker Ransomware Dark Web Portal Seized In International Sting (report)