{"id":38089,"date":"2023-11-03T20:57:04","date_gmt":"2023-11-03T20:57:04","guid":{"rendered":"https:\/\/zpesystems.com\/?p=38089"},"modified":"2023-11-08T21:32:37","modified_gmt":"2023-11-08T21:32:37","slug":"breaking-down-the-2023-ragnar-locker-cyberattacks","status":"publish","type":"post","link":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/","title":{"rendered":"Breaking Down The 2023 Ragnar Locker Cyberattacks"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;0px||||false|false&#8221; custom_padding=&#8221;0px||||false|false&#8221; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg&#8221; alt=&#8221;Breaking Down the 2023 Ragnar Locker Cyberattacks&#8221; title_text=&#8221;Breaking Down the 2023 Ragnar Locker Cyberattacks&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><em>This article was written by <a href=\"https:\/\/www.linkedin.com\/in\/jamescabe\/\">James Cabe, CISSP<\/a>, a 30-year cybersecurity expert who&#8217;s helped major companies including Microsoft and Fortinet.<\/em><\/p>\n<p><span style=\"font-weight: 400;\">Throughout 2023, several organizations were successfully hit by Ragnar Locker cyberattacks. The affected victims spanned the globe and were forced to shut down much of their critical operations, while the attackers demanded tens of millions of dollars in ransom payments. Despite the <\/span><a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/ragnar-locker-ransomware-gang-taken-down-international-police-swoop\"><span style=\"font-weight: 400;\">group being taken down by law enforcement<\/span><\/a><span style=\"font-weight: 400;\"> in October, organizations are re-evaluating their defensive measures \u2014 and more importantly, their recovery strategies \u2014 to combat these attacks.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you read my previous articles about the <\/span><a href=\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/\"><span style=\"font-weight: 400;\">ongoing MOVEit breach<\/span><\/a><span style=\"font-weight: 400;\"> and the <\/span><a href=\"https:\/\/zpesystems.com\/dissecting-the-mgm-cyberattack-lions-tigers-bears-oh-my\/\"><span style=\"font-weight: 400;\">ransomware that hit MGM<\/span><\/a><span style=\"font-weight: 400;\">, you probably know that isolation is key. It helps you fight through attacks by <\/span><a href=\"https:\/\/pipelinepub.com\/cybersecurity-assurance-2023\/preventing-ransomware-attacks\"><span style=\"font-weight: 400;\">cutting the kill chain<\/span><\/a><span style=\"font-weight: 400;\">, so that you can restore services quickly without reinfection.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>Who Carries Out Ragnar Locker Cyberattacks?<\/h1>\n<p><span style=\"font-weight: 400;\">Recent Ragnar Locker cyberattacks were carried out by the Dark Angels Team cybercriminal group. Dark Angels Team\u2019s modus operandi is to breach a company\u2019s defenses, spread laterally, and steal data that can be used to extort the target company. The approach they take involves gaining access to the Windows domain controller, where they deploy ransomware. They encrypt devices using Windows and ESXi encryptors, which gives organizations little recourse aside from taking their critical systems offline in order to stop the spread.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Dark-Angels-banner.webp&#8221; alt=&#8221;Dark Angels banner&#8221; title_text=&#8221;Dark Angels banner&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>How Do Ragnar Locker Cyberattacks Start?<\/h1>\n<p><span style=\"font-weight: 400;\">Ragnar Locker breaches, like all ransomware attacks, require a kill chain that must first be initiated. <\/span><a href=\"https:\/\/attack.mitre.org\/\"><span style=\"font-weight: 400;\">MITRE ATT&amp;CK<\/span><\/a><span style=\"font-weight: 400;\"> defines this as the \u2018initial,\u2019 and in these attacks, the initial comes from social engineering. Email stuffing is often the tactic of choice, whereby the attacker sends an email that appears to have a trail of replies or forwards (see the example below). Email trails like this trick spam filters and land directly in the target\u2019s inbox. When an employee clicks a malicious link inside the email, the attack kicks off.<\/span><\/p>\n<p><img decoding=\"async\" class=\"wp-image-38102 alignnone \" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Email-stuffing-example-from-marketer.png\" alt=\"An email showing an example of email stuffing.\" width=\"745\" height=\"526\" \/><\/p>\n<p>Image: Email stuffing is used by marketers and threat actors alike to bypass spam filters.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>How Do Companies Discover Ragnar Locker Cyberattacks?<\/h1>\n<p><span style=\"font-weight: 400;\">After the Ragnar Locker cyberattack kicks off, the bad link uses Java to load the locker ransomware, then a series of batch scripts installs a payload consisting of virtual box emulation software. This emulation software takes over and encrypts the host, and displays the ransomware message (see image below).<\/span><\/p>\n<p><img decoding=\"async\" class=\"wp-image-38103 alignnone \" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Ragnar-Locker-ransomware-message.jpg\" alt=\"A Ragnar Locker ransomware message shown in a notes file.\" width=\"735\" height=\"645\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Ragnar-Locker-ransomware-message.jpg 735w, https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Ragnar-Locker-ransomware-message-480x421.jpg 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 735px, 100vw\" \/><\/p>\n<p>Image: A Ragnar Locker ransomware message showing on encrypted devices.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>How Do Ragnar Locker Cyberattacks Spread?<\/h1>\n<p><span style=\"font-weight: 400;\">The attack spreads by gaining access to Windows domain controllers and then attacking the management interfaces of the VMware ESXi machines. Most organizations don\u2019t properly segment or isolate these management interfaces. This makes them especially vulnerable even to older Babuk ransomware source code that is an ESXi encryptor. Basically, the attackers only need to gain access to the management network, and then they can attack the production network.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">From Intel471: \u201cVMware\u2019s ESXi is called a \u2018<\/span><a href=\"https:\/\/www.vmware.com\/topics\/glossary\/content\/bare-metal-hypervisor.html\"><span style=\"font-weight: 400;\">bare metal<\/span><\/a><span style=\"font-weight: 400;\">\u2019 hypervisor because the underlying hardware on which it is installed doesn\u2019t need an operating system. ESXi allows the hardware to be utilized for multiple virtual machines (VMs), which saves on hardware costs. ESXi is a fruitful target for attackers since it may be connected to several VMs and the storage for them. Security experts<\/span><a href=\"https:\/\/vmiss.net\/vmware-esxi-ransomware-what-you-need-to-know\/\"> <span style=\"font-weight: 400;\">warn<\/span><\/a><span style=\"font-weight: 400;\"> ransomware actors have built specific binaries to target these systems. Groups joining this trend include HelloKitty, Black Basta, Cheerscrypt and GwisinLocker.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">They continue, \u201cOver the last few years, several vulnerabilities have been identified in ESXi, including<\/span><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-21974\"> <span style=\"font-weight: 400;\">CVE-2021-21974<\/span><\/a><span style=\"font-weight: 400;\">. The vulnerability is a heap overflow vulnerability within<\/span><a href=\"http:\/\/www.openslp.org\/\"> <span style=\"font-weight: 400;\">Open Service Location Protocol<\/span><\/a><span style=\"font-weight: 400;\"> (OpenSLP), which is a network discovery tool. The vulnerability is remotely exploitable over port 427, and has a Common Vulnerability Scoring System Version 3.0 (CVSSv3) base score of<\/span><a href=\"https:\/\/www.vmware.com\/security\/advisories\/VMSA-2021-0002.html\"> <span style=\"font-weight: 400;\">8.8<\/span><\/a><span style=\"font-weight: 400;\">. It\u2019s suspected that it may be the vulnerability exploited in this attack.<\/span><a href=\"https:\/\/blogs.vmware.com\/security\/2023\/02\/83330.html\"> <span style=\"font-weight: 400;\">VMware said<\/span><\/a><span style=\"font-weight: 400;\"> that \u201csignificantly out-of-date products\u201d were targeted with vulnerabilities that had been addressed. It affects ESXi versions 7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG and 6.5 before ESXi650-202102101-SG. Due to<\/span><a href=\"https:\/\/kb.vmware.com\/s\/article\/76372\"> <span style=\"font-weight: 400;\">other vulnerabilities<\/span><\/a><span style=\"font-weight: 400;\"> in OpenSLP, VMware disabled OpenSLP starting in 2021 in ESXi versions 7.0 U2c and ESXi 8.0, which is the current version.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Ultimately, these attacks exploit a combination of a lack of management plane isolation to the VMware management interfaces, specifically on port 427 (OpenSLP), and a lack of patching and updating. Organizations also typically lack a backup authentication mechanism for the control plane, as well as Privileged Access Management, which are both good fallback options.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>How Can Companies Stop Ragnar Locker Cyberattacks?<\/h1>\n<p><span style=\"font-weight: 400;\">Ragnar Locker ransomware and other attacks are successful because companies don\u2019t employ proper management plane isolation. Attackers can gain access to VMware management interfaces, and then they essentially have the keys to the kingdom. That\u2019s it. No amount of defense can save you.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If you recall <\/span><a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/binding-operational-directive-23-02\"><span style=\"font-weight: 400;\">CISA\u2019s binding operational directive<\/span><\/a><span style=\"font-weight: 400;\">, they call for an isolated management infrastructure. This is what we refer to as IMI. Rather than serving as a defense, like we think of traditional cybersecurity products, the IMI is an architecture that allows you to fight back. It\u2019s your quick-reaction force, your cavalry, your secret weapon that ensures you always have a counterattack ready to deploy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">IMI is infrastructure that is dedicated \u2014 and most importantly, fully isolated from production assets \u2014\u00a0to ensuring operations can recover quickly from breaches and outages. Here\u2019s a graphical breakdown:<\/span><\/p>\n<p><img decoding=\"async\" class=\"wp-image-36055 alignnone size-large\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/Isolated-Management-Network-Diagram-1024x576.png\" alt=\"Isolated Management Infrastructure diagram\" width=\"1024\" height=\"576\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/Isolated-Management-Network-Diagram-980x551.png 980w, https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/Isolated-Management-Network-Diagram-480x270.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/p>\n<p><span style=\"font-weight: 400;\">The IMI includes all of the tools you need for rerouting traffic, decommissioning affected gear, wiping\/re-imaging devices, and restoring infrastructure. You can also incorporate automation to speed the process along and make recovery something that happens in minutes or hours at the most. Aside from being completely isolated from production assets, the IMI itself is also segmented and employs zero trust practices. This means that you and only you have access to your secret weapon for cutting the ransomware kill chain.<\/span><\/p>\n<h1>How Do You Use Isolated Management Infrastructure?<\/h1>\n<p><span data-contrast=\"auto\">An IMI can host an <\/span><a href=\"https:\/\/zpesystems.com\/build-an-isolated-recovery-environment-zs\/\"><span data-contrast=\"none\">IRE (Isolated Recovery Environment)<\/span><\/a><span data-contrast=\"auto\">, which is used to cut off all user data and remote access (except for <\/span><a href=\"https:\/\/zpesystems.com\/in-band-vs-out-of-band-management-zs\/\"><span data-contrast=\"none\">OOB<\/span><\/a><span data-contrast=\"auto\">) to an entire infected site. A properly implemented recovery environment should automate most of these activities to speed up the recovery. One of the first considerations is the requirement for a secondary organization in your IAM that is not attached to normal operations. This is what is known as a set of \u201c<\/span><a href=\"https:\/\/thesysadminchannel.com\/break-glass-account-what-is-it-and-why-do-you-need-it\/\"><span data-contrast=\"none\">Break the Glass<\/span><\/a><span data-contrast=\"auto\">\u201d accounts. These are known in military circles but have made it into formal practice as part of a strong playbook for ransomware. Once you do this, you can instantiate selected Zero Trust remote access to the site using credentials that are not in the scope of the attack, and then bring up a communications channel for a virtual war room using software like Rocket Chat, Jitsi, Slack, or other standalone communications tools that are installable on the IRE environment.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:259}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Avoiding normal authentication methods or IAM and normal communication channels is required for the integrity of the recovery and strengthens the recovery playbook. During this time, no email may be used that is associated directly with the organization. Ideally, email should never touch an account that is associated with it either.<\/span><\/p>\n<p><span data-contrast=\"auto\">The next step is to create a new set of clean side networks that do not directly connect to the main backbone or put it behind another firewall for triage good\/bad. Using a sniffer software running on the IRE, the recovery team can then run a passive scan or an active scanner against all machines continuing to try to send email to Exchange\/M365. You can give access to people that are deemed good (not sending traffic) but lock off (with an EDR) the ability to open Outlook for a while, while keeping them on the web email. From there, continue working through to find all the sending drivers to see if they have a good backup. If not, back up the infected drive for offline data retrieval for later. Then re-image while scanning the UEFI BIOS during boot (if needed, run an IPMI scan). If the site has a list of assets that are considered crown jewels, prioritize these.<\/span><\/p>\n<p><span data-contrast=\"auto\">Once you have a segmented \u201cclean side\u201d established with all the network services required to operate the site (DNS, IAM, DHCP), then Internet access can be restored to this site on a limited basis; which means only out-bound communications, nothing in-bound. Restorative operations can continue apace. making sure that the infected side assets are captured in backup for later forensics following chain-of-custody if damages exceeding insurance limits are found to be the case. This is decided in the war room.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2>Download the Isolated Management Infrastructure Blueprint<\/h2>\n<p><span style=\"font-weight: 400;\">Now is the time to lay the groundwork for your IMI so you can fight back against ransomware. Download the Network Automation Blueprint, which gives you a step-by-step guide to building your Isolated Management Infrastructure.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;https:\/\/zpesystems.com\/network-automation-blueprint\/&#8221; button_text=&#8221;Download blueprint&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_button][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23.1&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2>Get in touch with me!<\/h2>\n<p><span style=\"font-weight: 400;\">True security can only be achieved through resilience, and that&#8217;s my mission. If you want help shoring up your defenses, building an IMI, and implementing a Resilience System, get in touch with me. Here are links to my social media accounts:<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/www.linkedin.com\/in\/jamescabe\/\">James Cabe &#8211; CISSP on LinkedIn<\/a><\/li>\n<li><a href=\"https:\/\/twitter.com\/how2cloud?lang=en\">@how2cloud on X &#8211; James Cabe<\/a><\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many organizations suffered Ragnar Locker cyberattacks in 2023. 30-year cybersecurity expert James Cabe discusses the problem and solution.<\/p>\n","protected":false},"author":5,"featured_media":38110,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","footnotes":""},"categories":[103,156,101,93,82,162,97,134],"tags":[],"class_list":["post-38089","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-improve-network-security","category-micro-segmentation","category-minimize-impact-of-disruptions","category-network-automation","category-out-of-band-management","category-secops","category-user-management","category-zero-trust-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v26.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Breaking Down The 2023 Ragnar Locker Cyberattacks<\/title>\n<meta name=\"description\" content=\"Many organizations suffered Ragnar Locker cyberattacks in 2023. 30-year cybersecurity expert James Cabe discusses the problem and solution.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Breaking Down The 2023 Ragnar Locker Cyberattacks\" \/>\n<meta property=\"og:description\" content=\"Many organizations suffered Ragnar Locker cyberattacks in 2023. 30-year cybersecurity expert James Cabe discusses the problem and solution.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/\" \/>\n<meta property=\"og:site_name\" content=\"ZPE Systems\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-03T20:57:04+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-11-08T21:32:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jordan Baker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jordan Baker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/\",\"url\":\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/\",\"name\":\"Breaking Down The 2023 Ragnar Locker Cyberattacks\",\"isPartOf\":{\"@id\":\"https:\/\/zpesystems.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg\",\"datePublished\":\"2023-11-03T20:57:04+00:00\",\"dateModified\":\"2023-11-08T21:32:37+00:00\",\"author\":{\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\"},\"description\":\"Many organizations suffered Ragnar Locker cyberattacks in 2023. 30-year cybersecurity expert James Cabe discusses the problem and solution.\",\"breadcrumb\":{\"@id\":\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#primaryimage\",\"url\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg\",\"contentUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg\",\"width\":1200,\"height\":627,\"caption\":\"James Cabe breaks down the 2023 Ragnar Locker cyberattacks\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/zpesystems.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Breaking Down The 2023 Ragnar Locker Cyberattacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/zpesystems.com\/#website\",\"url\":\"https:\/\/zpesystems.com\/\",\"name\":\"ZPE Systems\",\"description\":\"Rethink the Way Networks are Built and Managed\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/zpesystems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\",\"name\":\"Jordan Baker\",\"url\":\"https:\/\/zpesystems.com\/author\/jordan\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Breaking Down The 2023 Ragnar Locker Cyberattacks","description":"Many organizations suffered Ragnar Locker cyberattacks in 2023. 30-year cybersecurity expert James Cabe discusses the problem and solution.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/","og_locale":"en_US","og_type":"article","og_title":"Breaking Down The 2023 Ragnar Locker Cyberattacks","og_description":"Many organizations suffered Ragnar Locker cyberattacks in 2023. 30-year cybersecurity expert James Cabe discusses the problem and solution.","og_url":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/","og_site_name":"ZPE Systems","article_published_time":"2023-11-03T20:57:04+00:00","article_modified_time":"2023-11-08T21:32:37+00:00","og_image":[{"width":1200,"height":627,"url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg","type":"image\/jpeg"}],"author":"Jordan Baker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jordan Baker","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/","url":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/","name":"Breaking Down The 2023 Ragnar Locker Cyberattacks","isPartOf":{"@id":"https:\/\/zpesystems.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#primaryimage"},"image":{"@id":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#primaryimage"},"thumbnailUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg","datePublished":"2023-11-03T20:57:04+00:00","dateModified":"2023-11-08T21:32:37+00:00","author":{"@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567"},"description":"Many organizations suffered Ragnar Locker cyberattacks in 2023. 30-year cybersecurity expert James Cabe discusses the problem and solution.","breadcrumb":{"@id":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#primaryimage","url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg","contentUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg","width":1200,"height":627,"caption":"James Cabe breaks down the 2023 Ragnar Locker cyberattacks"},{"@type":"BreadcrumbList","@id":"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zpesystems.com\/"},{"@type":"ListItem","position":2,"name":"Breaking Down The 2023 Ragnar Locker Cyberattacks"}]},{"@type":"WebSite","@id":"https:\/\/zpesystems.com\/#website","url":"https:\/\/zpesystems.com\/","name":"ZPE Systems","description":"Rethink the Way Networks are Built and Managed","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zpesystems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567","name":"Jordan Baker","url":"https:\/\/zpesystems.com\/author\/jordan\/"}]}},"rttpg_featured_image_url":{"full":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg",1200,627,false],"landscape":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg",1200,627,false],"portraits":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg",1200,627,false],"thumbnail":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-150x150.jpg",150,150,true],"medium":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-300x157.jpg",300,157,true],"large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-1024x535.jpg",1024,535,true],"1536x1536":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg",1200,627,false],"2048x2048":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg",1200,627,false],"et-pb-post-main-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-400x250.jpg",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-1080x627.jpg",1080,627,true],"et-pb-portfolio-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-400x284.jpg",400,284,true],"et-pb-portfolio-module-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-510x382.jpg",510,382,true],"et-pb-portfolio-image-single":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-1080x564.jpg",1080,564,true],"et-pb-gallery-module-image-portrait":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-400x516.jpg",400,516,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg",1200,627,false],"et-pb-image--responsive--desktop":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks.jpg",1200,627,false],"et-pb-image--responsive--tablet":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-980x512.jpg",980,512,true],"et-pb-image--responsive--phone":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/11\/Breaking-Down-the-2023-Ragnar-Locker-Cyberattacks-480x251.jpg",480,251,true]},"rttpg_author":{"display_name":"Jordan Baker","author_link":"https:\/\/zpesystems.com\/author\/jordan\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/\" rel=\"category tag\">Improve Network Security<\/a> <a href=\"https:\/\/zpesystems.com\/category\/micro-segmentation\/\" rel=\"category tag\">Micro-segmentation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/minimize-impact-of-disruptions\/\" rel=\"category tag\">Minimize Impact of Disruptions<\/a> <a href=\"https:\/\/zpesystems.com\/category\/increase-productivity\/network-automation\/\" rel=\"category tag\">Network Automation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/remote-network-management\/out-of-band-management\/\" rel=\"category tag\">Out of Band Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/secops\/\" rel=\"category tag\">SecOps<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/user-management\/\" rel=\"category tag\">User Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/zero-trust-security\/\" rel=\"category tag\">Zero Trust Security<\/a>","rttpg_excerpt":"Many organizations suffered Ragnar Locker cyberattacks in 2023. 30-year cybersecurity expert James Cabe discusses the problem and solution.","_links":{"self":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/38089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/comments?post=38089"}],"version-history":[{"count":10,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/38089\/revisions"}],"predecessor-version":[{"id":38181,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/38089\/revisions\/38181"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media\/38110"}],"wp:attachment":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media?parent=38089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/categories?post=38089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/tags?post=38089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}