CSIDB logo
Threat actor

Ragnarok

Attribution profile

Type
Criminal
Location
China
Known incidents
2 incidents
First seen
2021-03-31
Last seen
2025-02-06
Updated
2026-07-31 04:52
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Ragnarok has been identified with the alias Ragnarok and is associated with a location in China according to available reporting. The actor first came to public attention through ransomware incidents targeting Italian organizations. No additional aliases have been documented in the sources provided. The actor has not been linked to any other pseudonyms in the publicly available material.

Ragnarok’s observed activity includes attacks on entities in the healthcare sector and the fashion retail sector, both located in Italy. The healthcare incident involved a medical laboratory in Cagliari, where attackers encrypted systems and exfiltrated sensitive administrative and clinical files. The retail incident affected a premium menswear brand in Milan, resulting in the alleged theft of approximately forty gigabytes of proprietary data. These cases indicate a focus on Italian organizations across different industries.

The actor’s methodology centers on the deployment of ransomware that bears the same name as the actor, Ragnarok. In the reported incidents, attackers provided proof of compromise via screenshots of file directories and claimed download links, although the links were non‑functional at the time of verification. No details about initial access vectors, privilege escalation techniques, or ancillary tooling have been disclosed in the open sources. The actor has used the same ransomware name in both incidents.

Two representative operations illustrate the actor’s pattern: the February 2025 ransomware attack on an Italian medical laboratory that compromised online report authorizations, laboratory documents, Covid‑19 regulatory references and quality control records, and the March 2021 ransomware incident against Boggi Milano in which approximately 40 GB of data was allegedly exfiltrated. Both events were attributed to Ragnarok by the respective reporting outlets. The actor’s known location in China remains the only geographic detail publicly linked to the group. No public statements have tied the group to a state sponsor or a larger criminal consortium.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB