Threat hunters have analyzed an advanced malware toolkit called Ragnar Loader that is used by various hacking groups and ransomware gangs, such as Ragnar Locker (also known as Monstrous Mantis), FIN7, FIN8, and Ruthless Mantis (formerly REvil).

“Ragnar Loader plays a key role in maintaining access to compromised systems, helping attackers remain in networks for long-term malicious activities,” said Swiss cybersecurity firm PRODAFT.
According to researchers, the toolkit has been linked to the Ragnar Locker group, but is likely rented to others. However, its developers are constantly adding new features, evolving it.
See also: BadBox malware disrupted on 500,000 infected Android devices
Ragnar Loader, also known as Sardonic, was first documented by Bitdefender in August 2021. It was used in an unsuccessful attack carried out by FIN8 targeting an anonymous financial institution in the US.
In July 2023, Symantec revealed the use of an updated version by FIN8 to deliver the now-defunct BlackCat ransomware.
The core functionality of Ragnar Loader is its ability to establish long-term access to targeted environments, while using multiple techniques to evade detection and ensure operational resilience.
“The malware uses PowerShell-based payloads for execution, incorporates strong encryption and encoding methods (including RC4 and Base64), and employs sophisticated process injection strategies to establish and maintain secret control over compromised systems,” PRODAFT notes.
Ragnar Loader is offered to cybercriminals in the form of an archive file package containing multiple components to facilitate reverse shell, local privilege escalation, and remote desktop access. It also establishes communications with the threat actor, allowing it to remotely control the infected system via a command and control (C2) console.
See also: New polyglot malware hits aviation and satellite communications companies
Ragnar Loader incorporates a number of anti-analysis techniques to resist detection. In addition, it can perform various backdoor operations, executing DLL plugins and shellcode. To enable lateral movement within a network, it uses another PowerShell-based pivoting file.

Another critical component of Ragnar Loader is an ELF Linux executable named bc, designed to facilitate remote connections, allowing the attacker to launch and execute command-line instructions directly on the compromised system.
See also: BackConnect malware links Black Basta and Cactus ransomware
How to protect yourself from this threat
✅ Model Zero Trust Security – Assume your network could already be compromised and restrict access based on strong authentication.
✅ Endpoint Detection & Response (EDR) – Use advanced threat detection tools to find hidden malware.
✅ Threat Hunting – Since Ragnar Loader focuses on persistence, security teams should actively scan for unusual behavior rather than waiting for alerts.
✅ Continuous Updates – Many attacks rely on exploiting old vulnerabilities in software and operating systems.
✅ Restrict Access – Use role-based access control and multi-factor authentication (MFA) to reduce the attack surface.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
