ATT&CKSoftwareRagnar Locker

Ragnar Locker

S0481

Malware.View on attack.mitre.org

About this malware

Ragnar Locker is a ransomware that has been in use since at least December 2019.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1059.003
Windows Command Shell

Ragnar Locker has used cmd.exe and batch scripts to execute commands.

T1120
Peripheral Device Discovery

Ragnar Locker may attempt to connect to removable drives and mapped network drives.

T1218.007
Msiexec

Ragnar Locker has been delivered as an unsigned MSI package that was executed with msiexec.exe.

T1218.010
Regsvr32

Ragnar Locker has used regsvr32.exe to execute components of VirtualBox.

T1218.011
Rundll32

Ragnar Locker has used rundll32.exe to execute components of VirtualBox.

T1486
Data Encrypted for Impact

Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom.

T1489
Service Stop

Ragnar Locker has attempted to stop services associated with business applications and databases to release the lock on files used by these applications so they may be encrypted.

T1490
Inhibit System Recovery

Ragnar Locker can delete volume shadow copies using vssadmin delete shadows /all /quiet.

T1543.003
Windows Service

Ragnar Locker has used sc.exe to create a new service for the VirtualBox driver.

T1564.006
Run Virtual Instance

Ragnar Locker has used VirtualBox and a stripped Windows XP virtual machine to run itself. The use of a shared folder specified in the configuration enables Ragnar Locker to encrypt files on the host operating system, including files on any mapped drives.

T1569.002
Service Execution

Ragnar Locker has used sc.exe to execute a service that it creates.

T1614
System Location Discovery

Before executing malicious code, Ragnar Locker checks the Windows API GetLocaleInfoW and doesn't encrypt files if it finds a former Soviet country.

T1685
Disable or Modify Tools

Ragnar Locker has attempted to terminate/stop processes and services associated with endpoint security products.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Cynet Ragnar Apr 2020 Open source
    Gold, B. (2020, April 27). Cynet Detection Report: Ragnar Locker Ransomware. Retrieved June 29, 2020.
  2. Sophos Ragnar May 2020 Open source
    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.