logo

Ransomware Tracker (Entry #231): WAGNER

ID: f84c7ef7-32f0-58c4-8d4d-3f0b7f43b56b

STIX ID: report--f84c7ef7-32f0-58c4-8d4d-3f0b7f43b56b

Feed Name: WatchGuard Secplicity Blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

The report describes the WAGNER ransomware—likely built with the Chaos v4.0 builder and linked by metadata and timing to the Wagner Group/Prigozhin context—using AES-256-CBC to encrypt files and RSA-1024 to protect AES keys; files larger than 2 MB are irreversibly overwritten, a Truesec decryptor exists for files under 2 MB, and the authors assess the campaign as pseudo-extortion rather than a genuine ransom operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.