A new pro-Ukrainian hacker group, identified as VantaCore, has begun targeting Russian organizations with custom ransomware. The group demands multi-million dollar payments from its victims. Researchers first detected VantaCore's activity in August, with its data-leak website appearing in early June.
Cybersecurity firm F6 suggests that VantaCore is a rebrand of Thor, another pro-Ukrainian hacking group active in 2023. Thor was responsible for at least 12 attacks, combining financial extortion with destructive or politically motivated actions. VantaCore, however, appears to be primarily focused on financial gain.
VantaCore operates as a ransomware-as-a-service (RaaS) model, providing malware and infrastructure to affiliates. They communicate with victims via a Tor-based chat service and maintain a leak site for stolen data. The group employs common infiltration methods, including exploiting poorly secured VPNs, flaws in internet-facing applications, and stolen login credentials.
What distinguishes VantaCore is its reliance on a suite of custom-built hacking tools. These include the VantaCore ransomware for encrypting data on servers and employee computers, VantaCoreLoader for distributing malware, VantaCoreRAT for system information gathering and remote execution, and SnowKiller, designed to disable security software like antivirus products.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new pro-Ukrainian hacker group named VantaCore is targeting Russian organizations with custom ransomware, demanding multi-million dollar payments. This group, believed to be a rebrand of the Thor ransomware operation, uses proprietary tools for encryption, distribution, and system control, indicating an evolution in their tactics.