Financially motivated cybercrime group targeting unpatched Citrix servers while filtering Russian and Chinese victims.
Analyst brief
Ragnarok is a financially motivated cybercrime group. It primarily targets organizations with unpatched Citrix servers, while filtering out Russian and Chinese victims based on system Language ID. Key TTPs include disabling Windows Defender and using AES with dynamically generated keys wrapped in RSA for encryption; its strings also reference UNIX file paths. Defenders should urgently patch Citrix servers, monitor for Windows Defender tampering, and watch for anomalous encryption activity on the network.
ragnarok
crime
According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers. It excludes Russian and Chinese targets using the system's Language ID for filtering. It also tries to disable Windows Defender and has a number of UNIX filepath references in its strings. Encryption method is AES using a dynamically generated key, then bundling this key up via RSA.