Skip to content

Malware

Ragnarok

According to Bleeping Computer, the ransomware is used in targeted attacks against unpatched Citrix servers.

Ragnarok is a Windows malware family.

Background

Bleeping Computer reports that this ransomware is deployed in targeted intrusions against unpatched Citrix servers. It checks the system's Language ID to skip victims in Russia and China, attempts to switch off Windows Defender, and contains numerous UNIX-style filepath strings. For encryption it applies AES with a dynamically generated key, which is then wrapped using RSA.


Source: Malpedia (Fraunhofer FKIE).