VantaCore is a ransomware group believed to be a rebrand of Thor, targeting Russian organizations with custom-built malware and multimillion-dollar ransom demands. F6 says the group has attacked at least seven victims, uses a ransomware-as-a-service model, and reflects a broader shift among pro-Ukrainian hackers toward in-house tooling instead of LockBit 3 Black and Babuk. #VantaCore #Thor #F6 #LockBit3Black #Babuk
Keypoints
- VantaCore is targeting Russian organizations with custom malware and large ransom demands.
- F6 says the group has at least seven known victims and may be a rebrand of Thor.
- The group operates as a ransomware-as-a-service platform with a Tor-based chat and leak site.
- VantaCore uses custom tools including VantaCore ransomware, VantaCoreLoader, VantaCoreRAT, and SnowKiller.
- Pro-Ukrainian groups are increasingly building their own malware instead of relying on LockBit 3 Black and Babuk.
Read More: https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia