Ragnar Locker

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[Ragnar Locker](https://attack.mitre.org/software/S0481) is a ransomware that has been in use since at least December 2019.(Citation: Sophos Ragnar May 2020)(Citation: Cynet Ragnar Apr 2020)

Associated Techniques (13)
ID ATT&CK Tactics
T1059.003 Windows Command Shell -
T1120 Peripheral Device Discovery -
T1218.007 Msiexec -
T1218.010 Regsvr32 -
T1218.011 Rundll32 -
T1486 Data Encrypted for Impact -
T1489 Service Stop -
T1490 Inhibit System Recovery -
T1543.003 Windows Service -
T1562.001 Disable or Modify Tools -
T1564.006 Run Virtual Instance -
T1569.002 Service Execution -
T1614 System Location Discovery -
Used by Actors (1)
Metadata
ID: 235
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00