RagnarLocker Ransomware Threatens to Release Confidential Information
ID: 447947c0-8c71-5a15-ad12-c388f56c4d4f
STIX ID: report--447947c0-8c71-5a15-ad12-c388f56c4d4f
Feed Name: McAfee Labs Blog
This technical report analyzes RagnarLocker ransomware: its 32-bit Windows binary, propagation and anti-analysis techniques (locale checks to avoid CIS languages, single-instance event logic), pre-deployment data theft and targeted deployment, file-encryption workflow (Salsa20 per-file keys encrypted with embedded RSA public key), credential and system discovery, service/process termination, shadow copy deletion, ransom note generation, and file extension/tagging behavior. The report provides multiple IOCs (SHA256 hashes), YARA detection rules, MITRE ATT&CK mappings, and notes McAfee/MVISION EDR detection and mitigation capabilities; it also references a high-profile incident with a near-$11M ransom demand.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
