Ragnarok Ransomware
Ragnarok is a newly observed ransomware tool that exploits the Citrix ADC and Gateway remote code execution vulnerability to propagate across vulnerable networks.
Summary
Ragnarok is a newly observed ransomware tool that exploits the Citrix ADC and Gateway remote code execution vulnerability to propagate across vulnerable networks.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, Ragnaork appears to be delivered manually. An unknown CVE-2019-19781 exploit is first deployed against identified vulnerable devices which, if successful, then downloads a small shell script. This script then searches for the python2 binary before downloading two additional files, one containing Ragnarok whilst the other contains a Meterpreter payload and the EternalBlue exploit, along with a scanner module. These files are then unpacked and executed.
Once installed, Ragnarok will attempt to encrypt all non-system files using an unknown algorithm before dropping a ransom note in each folder.
Remediation steps
| Type | Step |
|---|---|
|
Citrix has addressed CVE-2019-19781 in all affected products. Organisations are encouraged to review the following Citrix security pages and apply any relevant updates: If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Indicators of compromise
CVE Vulnerabilities
Last edited: 10 January 2022 4:45 pm