The Ragnar Locker ransomware operation's Tor trading and data leak sites were seized by law enforcement .

According to BleepingComputer, if someone tries to visit the two sites they will see a seizure message, stating that law enforcement authorities from the US, Europe, Germany, France, Italy, Japan, Spain, the Netherlands, the Czech Republic, and Latvia participated in the ransomware crackdown.
“This service was seized as part of a coordinated law enforcement action against the Ragnar Locker group,” the message states.
A Europol spokesperson confirmed that the seizure message is legitimate.
See also: Ukrainian Cyber Alliance: Hacked the Trigona ransomware gang
Ragnar Locker ransomware
Ragnar Locker (also known as Ragnar_Locker and RagnarLocker) is one of the most popular ransomware. It first appeared in late 2019 and targeted businesses.
Like other ransomware operations, Ragnar Locker breached corporate networks, spread to other devices, stole data, and then encrypted computers on the network.
Encrypted files and stolen data were used in double extortion attacks to put more pressure on the victim and increase the chances of paying the ransom.
However, Ragnar Locker was not considered Ransomware-as-a-Service (like many other modern ransomware). Instead, Ragnar Locker was semi-private, meaning that the hackers who created it did not actively promote its operation to recruit affiliates, but instead collaborated with external pentesters to breach networks.
See also: Chilean Government: Warns of Black Basta ransomware attacks
It is worth noting that in some cases, the ransomware gang carried out simple data theft attacks, without encryption, and used the data leak site to blackmail the victim.
According to cybersecurity researcher MalwareHunterTeam, RagnarLocker had recently switched to using a VMware ESXi encryptor based on the leaked Babuk ransomware source code.

However, a new ransomware operation called DarkAngels had used Ragnar Locker's original ESXi encryptor in an attack on Johnson Controls. It is unclear whether this new operation is a Ragnar Locker spin-off or rebranding, or if they purchased the source code.
However, Ragnar Locker ransomware is responsible for several attacks on well-known companies and organizations, including Energias de Portugal (EDP), Capcom, Campari, Dassault Falcon Jet, ADATA, and the city of Antwerp, Belgium.
The seizure of the Ragnar Locker ransomware trading site and leak site was a major success for international law enforcement.
The dark web, a haven for cybercriminals, is under significant attack from law enforcement. With the seizure of the gang , an important message has been sent to the global cyber-underworld: we do not tolerate illegal activities.
See also: NoEscape ransomware: Targets healthcare organizations
However, the problem of cyberattacks and extortion remains significant. More cooperation and coordination will be needed to put an end to this turbulent period of cybercrime.
So, while the fight against cybercrime continues, the seizure of Ragnar Locker's websites is a milestone in the effort to regain control of the threatened cyberspace.
Source: www.bleepingcomputer.com
