RagnarLocker (ELF)

First seen
2019-12-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:47:20

Targeted industries: energy-and-utilities financial-services government-and-public-sector healthcare-and-pharmaceutical manufacturing retail-and-hospitality

Context

RagnarLocker is a ransomware family known for encrypting files on systems and demanding a ransom for decryption keys. It employs a unique technique of deploying the ransomware as a virtual machine in order to evade detection by security software. RagnarLocker is often associated with double extortion tactics, threatening to release stolen data if the ransom is not paid.

Reports & references

  • twitter.com — 1475568201673105409 (report)
  • trellix.com — Analysis And Protections For Ragnarlocker Ransomware (report)
  • noticeofpleadings.com — 1%20 Microsoft%20Cobalt%20Strike%20 %20Complaint(907040021.9) (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Ragnarlocker (report)
  • techcrunch.com — Ragnarlocker Ransomware Dark Web Portal Seized In International Sting (report)

External references