cognitive cybersecurity intelligence

News and Analysis

Search

Ragnar Loader Employed By Multiple Ransomware Groups To Evade Detection

Ragnar Loader, also known as Sardonic Backdoor, is a sophisticated malware toolkit used in ransomware attacks by the Monstrous Mantis group (formerly Ragnar Locker). Discovered by security researchers, the malware maintains persistent access to compromised systems, using multi-layered obfuscation and dynamic decryption to challenge traditional security defenses. It utilizes PowerShell-based payloads, process injection strategies for stealthy control, and WMI filters for undetectable, fileless persistence. The loader is part of a toolkit enabling lateral movement and persistence within victim networks.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts