logo

RagnarLocker Ransomware Threatens to Release Confidential Information

ID: 447947c0-8c71-5a15-ad12-c388f56c4d4f

STIX ID: report--447947c0-8c71-5a15-ad12-c388f56c4d4f

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2020-06-09

Date Updated: 2026-04-28

Author: Alexandre Mundo

...
...

This technical report analyzes RagnarLocker ransomware: its 32-bit Windows binary, propagation and anti-analysis techniques (locale checks to avoid CIS languages, single-instance event logic), pre-deployment data theft and targeted deployment, file-encryption workflow (Salsa20 per-file keys encrypted with embedded RSA public key), credential and system discovery, service/process termination, shadow copy deletion, ransom note generation, and file extension/tagging behavior. The report provides multiple IOCs (SHA256 hashes), YARA detection rules, MITRE ATT&CK mappings, and notes McAfee/MVISION EDR detection and mitigation capabilities; it also references a high-profile incident with a near-$11M ransom demand.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.