VIKING SPIDER is a criminal group behind Ragnar Locker ransomware, known for double-extortion attacks on large enterprises.
Analyst brief
VIKING SPIDER is the criminal group responsible for the Ragnar Locker ransomware. It targets large enterprises and critical infrastructure organizations, employing a double-extortion tactic by threatening to leak exfiltrated data. The group operates a TOR-hosted DLS, has shown affiliations with other groups like MountLocker, and likely utilizes customized encryption algorithms. Defenders should focus on network segmentation, monitoring remote desktop services, and implementing robust data exfiltration detection.
VIKING SPIDER
unknown
VIKING SPIDER is the criminal group behind the development and distribution of Ragnar Locker ransomware. While public reporting indicates the group began threatening to leak victim data in February 2020, a DLS was not observed until April 2020. The DLS is hosted on Tor, and similar to other actors, proof of data exfiltration is provided before the stolen data is fully leaked. It was also noted that On Dec. 22, 2020, a new post made to MountLocker ransomware’s Tor-hosted DLS was titled 'Cartel News' and included details of a victim of VIKING SPIDER’s Ragnar Locker