Ransomware

Ragnarok

First seen: 2019-12 • Status: inactive

Currently Inactive

Ragnarok ransomware suddenly quit and released all their decryption keys. Victims can now decrypt for free.

Overview

Ragnarok suddenly shut down and released decryption keys. The group exploited Citrix and other vulnerabilities.

Also Known As

Asnarok

How It Spreads

  • Citrix exploitation
  • VPN vulnerabilities

What It Does

  • File encryption
  • Citrix targeting

Is your business exposed?

Target Platforms

Windows

Detection Tips

  • Historical - decryptors available

MITRE ATT&CK Techniques

T1486, T1190

If You're Infected

  1. 1.

    Use released decryption keys

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required