Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
The VantaCore ransomware group has struck at least seven victims in Russia using an entire malware stack developed in-house. The arsenal includes proprietary ransomware, a loader for lateral movement, a backdoor, and an antivirus-evasion module. According to Russian cybersecurity firm F6, VantaCore is a rebrand of Thor, a pro-Ukraine collective active in 2025 with at least twelve attributed attacks. Ransom demands reach millions of dollars.
- VantaCore has targeted at least seven Russian organizations with ransom demands reaching millions of dollars, operating under a ransomware-as-a-service model
- The group employs four proprietary tools: VantaCore ransomware for encryption, VantaCoreLoader for distribution and lateral movement, VantaCoreRAT for remote access and intelligence gathering, and SnowKiller to disable antivirus solutions
- F6 assesses VantaCore as a rebrand of Thor, a pro-Ukraine group active in 2025 with at least 12 attributed attacks, but no definitive confirmation links the operators of the two groups
- Initial access occurs via misconfigured VPNs, remote-access tools, vulnerabilities in internet-exposed applications, and compromised credentials
- F6 rates the tactics as "largely effective, though neither sophisticated nor innovative"
From Thor to VantaCore: F6's Reconstruction
F6 analysts have linked VantaCore to Thor, a pro-Ukraine group that amassed at least 12 attributed attacks in 2025. VantaCore's first activity was detected in August 2026, but the group's leak site dates to June of the same year. This timeline suggests a two-month infrastructure preparation period before declared operations began.
F6's reconstruction stops at the level of "belief" and "rebrand": it is not confirmed that Thor and VantaCore share the same operators. The dossier does not specify infrastructure overlap elements that would definitively link the two groups. This limitation matters for threat-actor tracking: the rebrand could conceal mergers, toolset acquisitions, or tactical marketing.
The VantaCore Quartet: How the Proprietary Arsenal Works
VantaCore's custom malware comprises four components with distinct functions. VantaCore ransomware encrypts data on servers and employee computers. VantaCoreLoader handles ransomware distribution and lateral movement within the compromised network. VantaCoreRAT serves as a backdoor for intelligence gathering, file transfer, and remote command execution. SnowKiller rounds out the suite by disabling security software, including antivirus.
This modular architecture is standard for the industry, but its in-house implementation is the novelty. According to F6, the group's tactics, techniques, and procedures are "largely effective, though neither sophisticated nor innovative." Technical parsimony does not prevent damage: initial access exploits well-known attack surfaces. Subsequent propagation exploits the predictable poor segmentation of target networks.
The RaaS Model and Monetization
VantaCore operates as ransomware-as-a-service. Victim communication runs through a Tor-based chat service. The group maintains a leak site for publishing stolen data. Ransom demands reach millions of dollars, placing VantaCore in the market's upper tier.
Exfiltrated data can be published, sold, or reused for further operations against Russian targets. This threefold option distinguishes VantaCore from purely financially motivated groups: the geopolitical component remains present, even if subordinated to profit. The RaaS model amplifies reach: external affiliates can conduct initial access, while VantaCore manages the brand, leak infrastructure, and negotiations.
"Researchers have seen some of these groups stop using widely available ransomware such as LockBit 3 Black and Babuk and instead build their own malware. The shift is partly driven by weaknesses found in those ransomware tools over time, as well as reluctance among pro-Ukrainian hackers to rely on software with Russian roots."
The Broader Phenomenon: When Hacktivism Becomes a Proprietary Industry
VantaCore's emergence fits into a broader reorganization of pro-Ukraine groups that F6 observed in 2025-2026. The shift from known lockers to custom malware has two drivers. The first is technical: weaknesses discovered over time in those tools. The second is political-cultural: reluctance to depend on software with Russian roots.
This trend finds convergent corroboration in another group monitored by F6, Bearlyfy, which has hit more than 70 Russian companies with custom ransomware. Bearlyfy's initial ransom demands hovered around 80,000 euros. Bearlyfy and VantaCore are distinct entities, but the coexistence of at least two groups with the same strategy indicates a structural shift in the ecosystem, not an isolated case.
What to Do Now
For organizations operating in Russia or with Russian supply chains, the F6 dossier suggests three concrete monitoring priorities. First: track rebrands of pro-Ukraine groups as a weakly reliable indicator of operational continuity, since identities, infrastructure, and toolsets can be rebuilt rapidly. Second: verify VPN configurations and exposure of internet-facing applications, documented initial-access vectors for VantaCore. Third: assess network segmentation, because the group's propagation exploits poor separation between corporate environments.
For threat intelligence analysts, the critical point is the singularity of the primary source: F6 via The Record. No other vendor has independently corroborated VantaCore's technical details. The dossier does not document victim names, targeted sectors, company sizes, nor shareable indicators of compromise. Attribution to Thor remains a working hypothesis, not an operational certainty.
Frequently Asked Questions
Is VantaCore linked to the Ukrainian government?
The source refers to "pro-Ukrainian hackers," not to an institutional link with the Ukrainian government or armed forces. The dossier contains no elements connecting the group to state structures.
Why did the group abandon LockBit and Babuk?
According to F6, the shift to custom malware is driven by technical weaknesses found in those lockers over time, and by operators' reluctance to use software with Russian origins.
Is the malware sophisticated?
No. F6 explicitly rates it as "neither sophisticated nor innovative," while acknowledging its operational effectiveness. The danger stems from the combination of initial access, persistence, and monetization, not from technical excellence.
Information is based on the cited source and current as of publication.
Sources
- https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia
- https://thehackernews.com/2026/03/bearlyfy-hits-70-russian-firms-with.html
- https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html
- https://www.schneier.com/blog/archives/2026/09/leaked-russian-cyber-operations-training-materials.html
- https://news.risky.biz/risky-bulletin-bgp-hijack-targets-virtualizor-to-deliver-malicious-updates/
- https://www.schneier.com/essays/archives/2024/05/llms-data-control-path-insecurity.html
- https://thehackernews.com/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.