Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Ragnarok ransomware operation shuts down and releases free decrypter
#1
https://therecord.media/ragnarok-ransomw...decrypter/      Catalin Cimpanu August 26, 2021
Ragnarok ransomware operation shuts down and releases free decrypter    The Ragnarok (or Asnarök) ransomware gang shut down their operation today and released a free decryption utility to help victims recover their files.

The free decrypter, hardcoded with a master decryption key, was released today on the gang’s dark web portal, where the group previously used to publish files from victims who refused to pay.    The decrypter, which has been confirmed to work by multiple security researchers, is currently being analyzed before security firms will rewrite a clean and safe-to-use version that will be made publicly available through Europol’s NoMoreRansom portal.

Prior to shutting down earlier today, the Ragnarok gang had been active since late 2019 and early 2020.

The gang operated by using exploits to breach a target company’s network and perimeter devices, from where it would pivot to internal networks and encrypt crucial servers and workstations.

To improve its chances of getting paid, the Ragnarok gang also stole files from victim networks, which it threatened to leak on its dark web portal unless the ransom was paid on time.

The group historically targeted Citrix ADC gateways and was also behind the campaign that exploited a zero-day in the Sophos XG firewalls. While the zero-day exploit worked and allowed the gang to backdoor XG firewalls across the world, Sophos spotted the attack in time to prevent the group from deploying its file-encrypting payload.

A month before shutting down today, the Ragnarok team changed the design of its site, removed most past victims, and later even rebranded as “Daytona by Ragnarok.”

    New leak site for Ragnarok ransomware pic.twitter.com/ZvbXt7LPpm
    — Catalin Cimpanu (@campuscodi) July 28, 2021

Ragnarok now becomes the third ransomware group that shuts down and releases a way for victims to recover files for free this summer, after the likes of Avaddon in June and SynAck earlier this month.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  AstraLocker ransomware shuts down and releases decryptors mrtrout 0 493 07-05-2022 , 03:28 AM
Last Post: mrtrout
  Operation Cyclone deals blow to Clop ransomware operation mrtrout 0 1,611 11-08-2021 , 01:02 AM
Last Post: mrtrout
  Amnesty International links cybersecurity firm to spyware operation mrtrout 0 555 10-11-2021 , 10:02 PM
Last Post: mrtrout
  Microsoft Warns of a Wide-Scale Phishing-as-a-Service Operation mrtrout 0 580 09-23-2021 , 08:09 PM
Last Post: mrtrout
  SynAck ransomware gang releases decryption keys for old victims mrtrout 0 638 08-13-2021 , 07:10 AM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)