Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Dallas Mavericks paid $33 million over three years by chimes for patches

Today’s Top Tech Startup Funding News on May 13, 2025

A $2.5 billion treasured chime file for IPO reveals a $33 million deal with the Dallas Mavericks

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » FIN7, FIN8, and others use permanent access and ransomware operations using RAGNAR loaders
Identity

FIN7, FIN8, and others use permanent access and ransomware operations using RAGNAR loaders

userBy userMarch 7, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 7, 2025Ravi Lakshmanan

Ragner Loader

Threat Hunter sheds light on a “sleek and evolving malware toolkit” called the Ragnar Loader used by various cybercrime and ransomware groups, including Ragnar Locker (aka Monstrous Mantis), Fin7, Fin8, and Ruthless Mantis (Ex-Revil).

“Ragnar Loader plays a key role in maintaining access to compromised systems and helping attackers stay on the network for long-term operation,” Swiss Cybersecurity Company Prodaft said in a statement shared with Hacker News.

“It’s linked to the Ragnar Locker Group, but it’s unclear whether they own it or borrow it from others. What we know is that its developers are constantly adding new features, making it more modular and difficult to detect.”

The Ragnar Loader, also known as Sardonic, was first documented by BitDefender in August 2021 in connection with a failed attack by FIN8 aimed at an unnamed financial institution in the US, which is said to be in use since 2020.

Cybersecurity

Then in July 2023, Symantec, owned by Broadcom, revealed that Fin8 used an updated version of the backdoor to provide the now-deprecated black cat ransomware.

The core function of the Ragnar Loader is its ability to establish long-term scaffolding within the target environment, while also using the arsenal of methods to avoid detection and ensure operational resilience.

“Malware is exploited to run powershell-based payloads, incorporating strong encryption and encoding methods (including RC4 and Base64) to hide operations, and employing sophisticated process injection strategies to stealth control and maintain compromised systems,” Prodaft said.

“These features collectively enhance our ability to avoid detection and sustain within the target environment.”

Ransomware Operation

Malware is provided to affiliates in the form of an archive file package containing multiple components to facilitate reverse shell, local privilege escalation, and remote desktop access. It is also designed to establish communication with threat actors, allowing remote control of infected systems via a command and control (C2) panel.

Typically, running on victim systems using PowerShell, Ragnar Loader integrates anti-analytic techniques to resist detection and obscure control flow logic.

Cybersecurity

Additionally, it has the ability to perform various backdoor operations by running DLL plugins and shellcode, reading and excludeing the contents of any file. Use a separate PowerShell-based pivot file to enable lateral movement within the network.

Another important component is a Linux executable file named BC, designed to facilitate remote connections. An attacker can directly execute and execute command line instructions on a compromised system.

“It employs advanced observation, encryption and anti-analytic techniques, including PowerShell-based payloads, RC4 and Base64 decryption routines, dynamic process injection, token manipulation, and lateral movement capabilities,” Prodaft said. “These features illustrate the increased complexity and adaptability of modern ransomware ecosystems.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOver 16,000 EV chargers are set up to be deployed in Midlands
Next Article Microsoft is reportedly planning the future without Openai
user
  • Website

Related Posts

Lead the Digital Revolution: Secure Exclusive TwinH Country Distribution Licenses

May 13, 2025

China Link APTS Exploit SAP CVE-2025-31324 581 Critical Systems Around the World

May 13, 2025

Malicious peepy package stealing source code that stole Solana Tools with 761 download

May 13, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Dallas Mavericks paid $33 million over three years by chimes for patches

Today’s Top Tech Startup Funding News on May 13, 2025

A $2.5 billion treasured chime file for IPO reveals a $33 million deal with the Dallas Mavericks

Flash flood evacuation at an elementary school in western Maryland

Trending Posts

Mali will disband all political parties after opposition says that opposition has been “arrested” | Political News

May 13, 2025

Iraq will release more than 19,000 prisoners under a new pardon. ISIL/ISIS News

May 13, 2025

Hakeem Jeffries exaggerated veteran share using food stamps? | Food News

May 13, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Today’s Top Tech Startup Funding News on May 13, 2025

Lead the Digital Revolution: Secure Exclusive TwinH Country Distribution Licenses

Can Your Digital Twin Make You Money? Discover the LEHT Opportunity

Microsoft is chasing thousands of employees despite quarterly profits of $25.8 billion. The biggest layoff since 2023

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.