HomeSecurityRagnar Locker ransomware: Strong blow from the authorities - Offline...

Ragnar Locker ransomware: Strong blow from authorities – Dark web sites offline

The Ragnar Locker ransomware operation's Tor trading and data leak sites were seized by law enforcement .

Ragnar Locker ransomware dark web

According to BleepingComputer, if someone tries to visit the two sites they will see a seizure message, stating that law enforcement authorities from the US, Europe, Germany, France, Italy, Japan, Spain, the Netherlands, the Czech Republic, and Latvia participated in the ransomware crackdown.

“This service was seized as part of a coordinated law enforcement action against the Ragnar Locker group,” the message states.

A Europol spokesperson confirmed that the seizure message is legitimate.

See also: Ukrainian Cyber ​​Alliance: Hacked the Trigona ransomware gang

Ragnar Locker ransomware

Ragnar Locker (also known as Ragnar_Locker and RagnarLocker) is one of the most popular ransomware. It first appeared in late 2019 and targeted businesses.

Like other ransomware operations, Ragnar Locker breached corporate networks, spread to other devices, stole data, and then encrypted computers on the network.

Encrypted files and stolen data were used in double extortion attacks to put more pressure on the victim and increase the chances of paying the ransom.

However, Ragnar Locker was not considered Ransomware-as-a-Service (like many other modern ransomware). Instead, Ragnar Locker was semi-private, meaning that the hackers who created it did not actively promote its operation to recruit affiliates, but instead collaborated with external pentesters to breach networks.

See also: Chilean Government: Warns of Black Basta ransomware attacks

It is worth noting that in some cases, the ransomware gang carried out simple data theft attacks, without encryption, and used the data leak site to blackmail the victim.

According to cybersecurity researcher MalwareHunterTeam, RagnarLocker had recently switched to using a VMware ESXi encryptor based on the leaked Babuk ransomware source code.

Ragnar Locker ransomware: Strong blow from authorities - Dark web sites offline

However, a new ransomware operation called DarkAngels had used Ragnar Locker's original ESXi encryptor in an attack on Johnson Controls. It is unclear whether this new operation is a Ragnar Locker spin-off or rebranding, or if they purchased the source code.

However, Ragnar Locker ransomware is responsible for several attacks on well-known companies and organizations, including Energias de Portugal (EDP), Capcom, Campari, Dassault Falcon Jet, ADATA, and the city of Antwerp, Belgium.

The seizure of the Ragnar Locker ransomware trading site and leak site was a major success for international law enforcement.

The dark web, a haven for cybercriminals, is under significant attack from law enforcement. With the seizure of the gang , an important message has been sent to the global cyber-underworld: we do not tolerate illegal activities. 

See also: NoEscape ransomware: Targets healthcare organizations

However, the problem of cyberattacks and extortion remains significant. More cooperation and coordination will be needed to put an end to this turbulent period of cybercrime. 

So, while the fight against cybercrime continues, the seizure of Ragnar Locker's websites is a milestone in the effort to regain control of the threatened cyberspace.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS