VantaCore: A New Ransomware Threat Targeting Russian Organizations with Custom Malware
A new ransomware group, **VantaCore**, believed to be linked to pro-Ukrainian hackers, is actively targeting Russian organizations. Utilizing a suite of custom-built malware, **VantaCore** is demanding multi-million dollar ransoms, marking a significant rebrand and shift in tactics within the pro-Ukrainian hacking landscape.
# VantaCore: A New Ransomware Threat Targeting Russian Organizations with Custom Malware
New research indicates the emergence of **VantaCore**, a ransomware group suspected of having ties to pro-Ukrainian hackers, which is now actively targeting Russian entities. The group is employing custom malware to inflict damage and demanding substantial, multi-million dollar payments.
According to a report published by Russian cybersecurity firm **F6**, **VantaCore** has been linked to at least seven known victims since its activity was first detected in August. The group's data-leak website, however, appears to have been established earlier, in early June.
## Rebranding from Thor
**F6** researchers suggest that **VantaCore** is a rebrand of **Thor**, another pro-Ukrainian hacking group that was notably active in targeting Russia last year. **Thor** was attributed to at least 12 attacks in 2025, often combining financial extortion with politically motivated or destructive actions.
While **Thor**'s operations had a dual focus, **VantaCore** appears to be primarily driven by financial gain, with ransom demands frequently reaching into the millions.
## Ransomware-as-a-Service Model
**VantaCore** operates on a ransomware-as-a-service (RaaS) model. In this structure, the core developers provide the necessary malware and infrastructure to affiliates who then execute the attacks. Communication with victims is handled via a Tor-based chat service, and a dedicated leak site is maintained for publishing stolen information.
### Infiltration Tactics
The group employs several common, yet effective, methods to breach corporate networks. These include exploiting inadequately secured VPNs and other remote-access tools, leveraging vulnerabilities in internet-facing applications, and utilizing login credentials obtained from business partners.
"Their tactics, techniques and procedures are largely effective, although they are neither sophisticated nor innovative," **F6** noted in their report.
## Custom Toolset
What truly distinguishes **VantaCore** from many other ransomware operations is its reliance on a unique collection of custom-built hacking tools:
* **VantaCore Ransomware**: Detected in August attacks, this proprietary ransomware is capable of encrypting data across both servers and individual employee workstations.
* **VantaCoreLoader**: This custom tool is used to distribute the **VantaCore** ransomware and other malicious software throughout compromised networks.
* **VantaCoreRAT**: A backdoor designed to gather system information, facilitate file transfers, and execute remote commands.
* **SnowKiller**: This tool specifically targets and disables security software, including antivirus products.
## Beyond Extortion
Similar to other pro-Ukrainian hacking groups, **VantaCore** may leverage stolen data for purposes beyond mere extortion. **F6** warns that information exfiltrated from Russian organizations could be published or sold online, potentially paving the way for further cyberattacks or other operations against Russian companies and individuals.
## A Broader Reorganization
The emergence of **VantaCore** aligns with a broader observed reorganization among pro-Ukrainian hacking groups during 2025 and 2026. **F6** has noted a shift where some of these groups are moving away from widely available ransomware strains like **LockBit 3 Black** and **Babuk**.
This transition is partly attributed to the discovery of weaknesses in these established ransomware tools over time, as well as a reluctance among pro-Ukrainian hackers to depend on software with perceived Russian origins.