ralord
- First seen
- 2018-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:56:19
Targeted industries: healthcare-and-pharmaceutical financial-services
Context
Ralord is a ransomware known for targeting various sectors, predominantly healthcare and financial services. It encrypts victims' files and demands payment for decryption keys. This family has been linked to multiple attacks since its emergence.
Detection coverage
- 2 YARA rules
Detection rules
- SIGNATURE_BASE_MAL_WIN_Ralordv1_Apr25 (yara-rule)
- MALPEDIA_Win_Ralord_Auto (yara-rule)
Reports & references
- ransomlook.io — Ralord (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ralord (report)
- ish.com.br — Ralord Novo Grupo De Ransomware As A Service 1 (report)
- x.com — 1905020136211275777 (report)