news.mlab.sh
Back to the feed
threat-intel

New pro-Ukraine hacker group targets Russian companies with custom ransomware

High
Summary

A new pro-Ukrainian hacker group, VantaCore, is targeting Russian companies with custom ransomware, demanding multi-million dollar payments. The group, believed to be a rebrand of Thor, utilizes a suite of custom-built tools to infiltrate networks and exfiltrate data, often leveraging stolen information for further attacks. This shift away from widely used ransomware tools reflects a broader trend among pro-Ukrainian hacking groups seeking to avoid reliance on Russian-based software.

A new pro-Ukrainian hacker group, VantaCore, is targeting Russian organizations with custom ransomware, demanding multi-million dollar payments. The group, believed to be a rebrand of Thor, a pro-Ukrainian hacking group active in 2025, utilizes a suite of custom-built tools to infiltrate networks and exfiltrate data, often leveraging stolen information for further attacks. Researchers first detected VantaCore's activity in August, with its data-leak website appearing in early June.

Like other pro-Ukrainian hacking groups, VantaCore may use stolen data for more than just extortion, with F6 stating that information taken from Russian organizations can be published or sold online and potentially used in further cyberattacks or other operations targeting Russian companies and individuals. The group operates as a ransomware-as-a-service operation, with affiliates carrying out attacks on behalf of VantaCore.

Researchers have observed a broader reorganization of pro-Ukrainian hacking groups during 2025 and 2026, with some groups moving away from widely available ransomware such as LockBit 3 Black and Babuk and instead building their own malware. This shift is partly driven by weaknesses found in those ransomware tools over time, as well as reluctance among pro-Ukrainian hackers to rely on software with Russian roots.

VantaCore communicates with victims through a Tor-based chat service and maintains a leak site where stolen information can be published. The group uses several common methods to break into corporate networks, including exploiting poorly secured VPNs and other remote-access tools, flaws in internet-facing applications and login credentials stolen from business partners.

Researchers have detected attacks in August involving VantaCore's proprietary ransomware, also called VantaCore, which can encrypt data on both servers and employees' computers. The group also deploys VantaCoreLoader, a backdoor that can gather information about infected systems, transfer files and remotely execute commands. Another tool, dubbed SnowKiller, is designed to disable security software, including antivirus products.

Read the full article at The Record