Ragnarok — Ransomware Profile
Ragnarok was a ransomware family used in targeted intrusions, first appearing in threat reports at the start of January 2020, with the earliest known sample dated to the end of 2019. FireEye reported attacks that reached victim networks through the Citrix ADC vulnerability CVE-2019-19781. Once inside, the operators spread the payload by scanning for EternalBlue-vulnerable Windows hosts and injecting a DLL that downloaded and installed the encryptor, while the malware added Windows group policies that disabled Windows Defender protections before encrypting. The binary checked the installed Windows language ID and skipped encryption on machines configured for Russian, Belarusian, Ukrainian, Kazakh, Azerbaijani, Latvian, Turkmen or Chinese. The same operation is also tracked as Asnarok, and reporting credits it with the campaign that exploited a Sophos XG firewall zero-day, a second route into victim networks. In December 2024 the US Treasury sanctioned Sichuan Silence, a Chengdu-based cybersecurity government contractor, and its employee Guan Tianfeng over that April 2020 firewall compromise, stating that Guan also attempted to infect victims with the Ragnarok variant. In August 2021 the operation ceased activity and released its private keys along with instructions to decrypt victims' data.Also tracked as
Asnarok, Asnarök
Vendor research
- Ragnarok: response and recovery actions INCIBE-CERT (Spanish National Cybersecurity Institute)
- Treasury Sanctions Cybersecurity Company Involved in Compromise of Firewall Products and Attempted Ransomware Attacks U.S. Department of the Treasury
- Ragnarok (Malware Family) Fraunhofer FKIE (Malpedia)