Ragnar Locker was an elite ransomware group targeting critical infrastructure with double-extortion tactics.
Analyst brief
Ragnar Locker was an elite ransomware group active from December 2019 to October 2023, targeting large enterprises and critical infrastructure, with at least 168 claimed victims including Capcom and Campari. The group primarily employed custom encryption algorithms and a dangerous double-extortion TTP, combining data exfiltration with file encryption. They typically gained initial access through exposed RDP services and conducted extensive reconnaissance before deploying ransomware. Although the group was dismantled by a Europol-led operation in October 2023, defenders should still focus on strong network segmentation, immutable offline backups, and strict access controls for remote desktop protocols to defend against similar threats.
ragnarlocker
crime
Ragnar Locker was an elite ransomware group active from December 2019 to October 2023 that targeted large enterprises and critical infrastructure — including Capcom and Campari — claiming at least 168 victims before being taken down by a Europol-led international law enforcement operation in October 2023.