Malware.View on attack.mitre.org
Ragnar Locker is a ransomware that has been in use since at least December 2019.
| Technique | Procedure example |
|---|---|
| T1059.003 Windows Command Shell |
Ragnar Locker has used cmd.exe and batch scripts to execute commands. |
| T1120 Peripheral Device Discovery |
Ragnar Locker may attempt to connect to removable drives and mapped network drives. |
| T1218.007 Msiexec |
Ragnar Locker has been delivered as an unsigned MSI package that was executed with |
| T1218.010 Regsvr32 |
Ragnar Locker has used regsvr32.exe to execute components of VirtualBox. |
| T1218.011 Rundll32 |
Ragnar Locker has used rundll32.exe to execute components of VirtualBox. |
| T1486 Data Encrypted for Impact |
Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom. |
| T1489 Service Stop |
Ragnar Locker has attempted to stop services associated with business applications and databases to release the lock on files used by these applications so they may be encrypted. |
| T1490 Inhibit System Recovery |
Ragnar Locker can delete volume shadow copies using |
| T1543.003 Windows Service |
Ragnar Locker has used sc.exe to create a new service for the VirtualBox driver. |
| T1564.006 Run Virtual Instance |
Ragnar Locker has used VirtualBox and a stripped Windows XP virtual machine to run itself. The use of a shared folder specified in the configuration enables Ragnar Locker to encrypt files on the host operating system, including files on any mapped drives. |
| T1569.002 Service Execution |
Ragnar Locker has used sc.exe to execute a service that it creates. |
| T1614 System Location Discovery |
Before executing malicious code, Ragnar Locker checks the Windows API |
| T1685 Disable or Modify Tools |
Ragnar Locker has attempted to terminate/stop processes and services associated with endpoint security products. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.