The End Of 'Ragnarok' Ransomware Gang

Ransomware attacks are on the rise following the 'COVID-19' coronavirus pandemic, simply because an increasing number of people are working and studying remotely, exposing more computers and devices to the internet.

However, one ransomware gang is not trying to benefit from this trend.

Ragnarok is a ransomware gang, best known for using the Ragnar Locker ransomware to target IT networks. It has claimed dozens of victims after exploiting a Citrix ADC vulnerability to search for Microsoft Windows systems that are vulnerable to the EternalBlue vulnerability, which is the same bug behind the notorious WannaCry attacks.

The cybercriminals have also stolen 10 terabytes worth of data belonging to Portuguese energy giant EDP, and threatened to leak it if a ransom of $10.9 million was not paid. The gang went on to exfiltrate up to 2 terabytes of data, including bank statements, employee records, and celebrity agreements, from the servers of Italian liquor giant Campari Group, and demanded it hands over $15 million in ransom.

It also targeted Capcom, the Japanese video games giant, and has reportedly stole the personal data of its 390,000 customers, business partners, and other external parties.

In all, the gang has racked up more than $4.5 million in ransom payments, according to reports.

Ragnarok decryptor
The ransomware gang provides a decryptor on its dark web website.

However, the gang doesn't seem to care about profiting again, as its operations have been terminated.

The ransomware gang that is also referred to as the Asnatok, has replaced all 12 of its victims listed on its dark web portal with a short instruction on how to decrypt files.

The message is accompanied by a decryptor, which contains a master decryption key to decrypt the files.

The ransomware gang does not mention or say anything about its reason. What it should be noted, the gang has adopted a similar self-destruction strategy similar to REvil, which mysteriously disappeared from the internet.

It is said that ransomware gangs are becoming targets of U.S government, in which its officials declared that they are a national security threat.

And Ragnarok has only been active for about a year and a half.

It’s possible the group had reached a pre-determined goal and wanted to make an exit before the authorities are after them.