CSIDB logo
Threat actor

Ragnar Locker

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
31 incidents
First seen
2019-06-12
Last seen
2023-04-04
Updated
2026-08-02 00:59
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as Ragnar Locker, also referred to as the Ragnar Locker Team, is a ransomware group that has been active since at least late 2019. Open source reporting indicates the group is believed to be based in Russia. Ragnar Locker employs a double extortion model, exfiltrating sensitive data before encrypting systems and threatening to publish the stolen information if a ransom is not paid. The group’s communications and leak sites are hosted on Tor‑hidden services, and they have used hacked Facebook accounts to run ads that pressure victims into paying. Financially motivated, they demand payment in cryptocurrency and have claimed multi‑terabyte data thefts from victims.

Targeting has spanned multiple sectors including municipal governments, healthcare providers, transportation companies, energy firms, chemical distributors, and critical infrastructure operators. Incidents have been reported in Europe (Portugal, Italy, Greece, Belgium, Switzerland, France) as well as in the United States and Brazil, showing a trans‑national focus. Examples of victimized entities are a Portuguese airline, a Greek natural gas operator, an Italian hospital, a Belgian police zone, and a Swiss railway operator. The group has also hit professional services such as lawyers’ associations and large customer‑support providers. Their activity is not limited to a single industry, reflecting a broad opportunistic approach to targets that possess valuable data.

Initial access frequently involves brute‑forcing or using stolen credentials against exposed Remote Desktop Protocol services. After gaining a foothold, the actors elevate privileges by exploiting known Windows vulnerabilities such as CVE‑2017‑0213 in the COM Aggregate Marshaler. To evade detection they sometimes deploy a VirtualBox virtual machine running a Windows XP image, which allows the ransomware process to run inside a trusted virtual environment. Lateral movement is carried out with PowerShell scripts, and they delete existing volume shadow copies and disable identified antivirus products before encryption. Data is exfiltrated to attacker‑controlled servers, and a Tor‑based negotiation site is provided for ransom discussions, while a public leak site is used to publish stolen material when demands are not met.

Notable operations include the 2022 attack on an Italian hospital where approximately one terabyte of personal and medical data was allegedly exfiltrated without prior encryption. In late 2022 the group mistakenly breached a Belgian police unit instead of the intended municipality, exposing years of personnel records, crime reports, surveillance metadata and traffic camera footage. The Greek national gas operator was hit in 2022, leading to confirmed impacts on system availability and possible leakage of directories and files. Ragnar Locker claimed to have stolen 1.5 TB from Taiwanese memory maker ADATA, 2 TB from Italian beverage company Campari, and over 10 TB from Portuguese energy giant EDP, attaching multi‑million‑dollar ransom demands in Bitcoin. Other publicly cited victims comprise the Japanese game developer Capcom, the customer‑support firm TTEC, and the Portuguese airline TAP Air Portugal, each accompanied by alleged large‑scale data theft and ransom negotiations.

Incidents

Attributed incidents are available to members.

31 incidents
CSIDB