Ragnarok Threat Actor Shuts Down Operations, Decryptor Released

After a series of news reports about huge ransomware hits, disastrous network takedowns and painful recoveries, the clouds seem to finally be dispersing a bit. Researchers reported that the ransomware gang known under the names Ragnarok and Asnarok has shut down its operations.

The announcement was made on the web page used by the hackers running Ragnarok. The page was updated with a download link for a toolset that can be used as a universal decryptor for anyone who still has files encrypted by the Ragnarok ransomware.

Security researchers have tested the decryptor and there are multiple reports that it works as intended and can successfully restore files to normal. The decryption tools are being picked apart and reverse engineered at the moment, so that an official, clean version can be posted up on the Europol NoMoreRansom portal page.

Ragnarok is a threat actor that was first spotted and documented by security researchers in late 2019. The hackers picked up in attacks and activity in 2020. However, after just a year and a half of active operation they officially close up shop in late August 2021.

This move, while refreshing, is not as surprising as it might seem. Earlier in the summer of 2021 two other threat actors dealing in ransomware also called it quits and released their own universal decryption tools for their respective strains of ransomware. Those two were named Avaddon and SynAck.

Following the ransomware attack on Colonial Pipeline and the following countermeasures taken by the US government, it looks like ransomware actors worldwide have started reconsidering their options. Two huge ransomware gangs - REvil and DarkSide, also seemingly shut down. A number of dark web hacking forums banned discussions revolving around ransomware entirely too.

Whether REvil and DarkSide are gone for good or are simply laying low for a while and quietly improving their toolkits in an effort to re-brand remains to be seen. At any rate, the news of Ragnarok closing down is a breath of fresh air in an otherwise bleak landscape.

August 30, 2021
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.