news.mlab.sh
Back to the feed
threat-intel

VectraRAT Can Hack Windows Enterprises for $250 per Month

High
Summary

A new, fully-developed malware-as-a-service (MaaS) platform called VectraRAT has emerged, offering a comprehensive remote access solution for enterprises for just $250 per month. Developed by a single operator (previously known as Nyxel) over the past four years, VectraRAT distinguishes itself through its complete custom-built architecture, UAC bypass capabilities, and sophisticated C2 protocols. The platform is delivered via social engineering vectors like ClickFix and is targeting high-value corporate Windows systems, seeking to exfiltrate data and establish persistent access. SOCRadar has provided indicators of compromise (IoCs) to assist defenders in mitigating the threat.

A new malware-as-a-service (MaaS) platform, VectraRAT, is gaining attention in the cybersecurity community. Developed by a single operator, previously known as Nyxel, over the past four years, VectraRAT provides a complete remote access solution for Windows enterprises at a price of $250 per month. Unlike other MaaS platforms that rely on repurposed malware, VectraRAT is built entirely from scratch, incorporating a full-featured Windows implant, command-and-control (C2) infrastructure, and an operator panel.

Researchers from SOCRadar discovered the platform in June 2023, after investigating an open directory that led to over 10 servers, dozens of samples, and operator logs. The developer offered add-on services, including crypting services, for between $100 and $350 per month, and a bundled package for over $2,000. The operator also demonstrated how the platform could evade antivirus detection by scanning against various products and versions.

VectraRAT delivers its payload through social engineering vectors like Amadey loader and ClickFix. Once installed, it provides attackers with a hidden desktop, remote CMD and PowerShell access, keylogging, file transfer, process discovery, clipboard manipulation, and SOCKS5 proxy functionality. The platform automatically collects browser credentials and searches for sensitive files, such as .env, .conf, and .config files, to provide persistent interactive access and facilitate further malicious activities, including data exfiltration.

What sets VectraRAT apart is its UAC bypass technique, which allows an attacker to obtain a high-integrity process without prompting the user for elevation. This feature significantly enhances the platform's capabilities and makes it more effective against security measures. The platform is targeting high-value corporate Windows systems, including Windows Enterprise, Enterprise LTSC, and Windows Server 2025, with a focus on exfiltrating data.

SOCRadar has provided organizations with indicators of compromise (IoCs), including a C2 override file, outbound TCP 3308: auto-elevation abuse, a debug API sequence, and a hidden PowerShell, to assist in detecting and mitigating the threat. The researchers also advise caution against ClickFix as an initial entry vector, recommending a single rule to close the delivery path used in the most active campaign documented. The emergence of VectraRAT highlights the ongoing trend of subscription-based, professionally developed attack infrastructure lowering the technical barrier for cybercriminals and presenting a new challenge for defenders.

Read the full article at Dark Reading