Threat Actor Profile

Viking Spider

Viking Spider is a cybercriminal group known for developing and deploying the Ragnar Locker ransomware. Emerging in late 2019, the group employs big game hunting (BGH) tactics to target high-value organizations. They are linked to the broader "Ransom Cartel," a network of ransomware operators.

Threat Actor Profile

Viking Spider

Fancy Bear TTPs

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Country of Origin

The exact country of origin for Viking Spider is unknown. However, their operations suggest ties to Eastern Europe, with some overlap in tactics and infrastructure with other Russian-speaking cybercriminal groups.

Members

The size and composition of Viking Spider remain unclear. They are believed to operate as a small, specialized team within the larger Ransom Cartel network.

Leadership

No specific leaders or aliases have been publicly identified for Viking Spider. Their operational secrecy and use of Tor-hosted leak sites make attribution challenging.

Tactics

The group primarily focuses on financial extortion through ransomware attacks, targeting industries with high-value data.

Techniques

They gain initial access through phishing campaigns and exploit vulnerabilities in remote desktop protocols (RDP). Once inside, they deploy Ragnar Locker ransomware to encrypt data.

Procedures

  • Use of Ragnar Locker ransomware

  • Hosting data leak sites on Tor

  • Proof of data exfiltration before full leaks

  • Avoiding targets in Russia and former Soviet states

Want to shut down threats before they start?

Indicators of Compromise (IOCs)

Organizations should monitor for:

  • Known Fancy Bear malware signatures (e.g., XAgent, ADVSTORESHELL).
  • Suspicious domains mimicking government or defense entities.
  • Zero-day exploits in applications like Microsoft Windows and Adobe Flash.
  • Abnormal network traffic patterns indicating command-and-control communications.

Key Victims

Fancy Bear targets include:

  • Governments (United States, Germany, France, Ukraine, and others).
  • Military Organizations (focus on NATO-aligned entities).
  • Media Outlets and Journalists (especially those covering Kremlin-related topics).
  • Critical Infrastructure (energy, aerospace, and defense).
  • International Sporting Organizations (e.g., WADA).
  • Political Groups (e.g., the Democratic National Committee).

Notable Cyber Attacks

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Notable Cyberattacks

  • 2020: Initiated data leak extortion campaigns, threatening to publish stolen data.

  • 2021: Linked to ransomware attacks on critical infrastructure and healthcare facilities.

Glitch effectGlitch effect

How to Defend Against Viking Spider

1

Regularly update and patch systems.

3

Conduct phishing awareness training.

Huntress solutions help protect organizations by monitoring endpoints, detecting intrusions, and mitigating threats with enterprise-grade technology.

Law Enforcement & Arrests

There have been no confirmed arrests of Viking Spider members. However, global law enforcement agencies, including Europol and the FBI, continue to monitor their activities.

References

Related Threat Actor Profiles

Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.

Detect, Respond, Protect

See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.

Try Huntress for Free