New pro-Ukraine hacker group targets Russian companies with custom ransomware

New pro-Ukraine hacker group targets Russian companies with custom ransomware
VantaCore is a ransomware group believed to be a rebrand of Thor, targeting Russian organizations with custom-built malware and multimillion-dollar ransom demands. F6 says the group has attacked at least seven victims, uses a ransomware-as-a-service model, and reflects a broader shift among pro-Ukrainian hackers toward in-house tooling instead of LockBit 3 Black and Babuk. #VantaCore #Thor #F6 #LockBit3Black #Babuk

Keypoints

  • VantaCore is targeting Russian organizations with custom malware and large ransom demands.
  • F6 says the group has at least seven known victims and may be a rebrand of Thor.
  • The group operates as a ransomware-as-a-service platform with a Tor-based chat and leak site.
  • VantaCore uses custom tools including VantaCore ransomware, VantaCoreLoader, VantaCoreRAT, and SnowKiller.
  • Pro-Ukrainian groups are increasingly building their own malware instead of relying on LockBit 3 Black and Babuk.

Read More: https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia