← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

VantaCore, a new pro-Ukraine hacker group, targets Russian companies with custom ransomware

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • VantaCore targets Russian companies with custom ransomware.
  • The group demands multi-million dollar payments.
  • VantaCore is believed to be a rebrand of the Thor hacking group.
  • They use custom tools: VantaCore ransomware, VantaCoreLoader, VantaCoreRAT, and SnowKiller.

New Ransomware Group Emerges

A new pro-Ukrainian hacker group, identified as VantaCore, has begun targeting Russian organizations with custom ransomware. The group demands multi-million dollar payments from its victims. Researchers first detected VantaCore's activity in August, with its data-leak website appearing in early June.

Connection to Previous Operations

Cybersecurity firm F6 suggests that VantaCore is a rebrand of Thor, another pro-Ukrainian hacking group active in 2023. Thor was responsible for at least 12 attacks, combining financial extortion with destructive or politically motivated actions. VantaCore, however, appears to be primarily focused on financial gain.

Operational Model and Tactics

VantaCore operates as a ransomware-as-a-service (RaaS) model, providing malware and infrastructure to affiliates. They communicate with victims via a Tor-based chat service and maintain a leak site for stolen data. The group employs common infiltration methods, including exploiting poorly secured VPNs, flaws in internet-facing applications, and stolen login credentials.

Custom Toolset

What distinguishes VantaCore is its reliance on a suite of custom-built hacking tools. These include the VantaCore ransomware for encrypting data on servers and employee computers, VantaCoreLoader for distributing malware, VantaCoreRAT for system information gathering and remote execution, and SnowKiller, designed to disable security software like antivirus products.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~30 min · 24 stories · Sep 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A new pro-Ukrainian hacker group named VantaCore is targeting Russian organizations with custom ransomware, demanding multi-million dollar payments. This group, believed to be a rebrand of the Thor ransomware operation, uses proprietary tools for encryption, distribution, and system control, indicating an evolution in their tactics.