Unidentified 103 (FIN8)
Aliases: Ragnar Loader, Sardonic
- Malware type
- loader
- Family
- Malware family
- Profile updated
- 2026-07-07 13:21:27
Targeted industries: financial-services retail-and-hospitality
Targeted regions: country_code:us country_code:ca
Context
A malware that uses .NET to load unmanaged (shell)code which has some resemblance to BADHATCH, the IP found in the sample was referred to in coverage on WHITERABBIT ransomware attacks.
Reports & references
- Broadcom/Symantec — Syssphinx Fin8 Backdoor (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Unidentified 103 (report)
- otx.alienvault.com — 61E7F74A936Eea5D44026B8E (report)
- github.com — Ragnarloader (report)