VanHelsing RaaS Launch: 3 Victims, $5K Entry Fee, Multi
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-55591 | Unauthenticated Super-Admin Bypass in Fortinet FortiOS and FortiProxy CVE-2024-55591 is an authentication bypass (CWE-288) in the Node.js websocket module of Fortinet FortiOS and FortiProxy that lets a remote, unauthenticated attacker gain super-admin privileges via crafted websocket requests. It affects FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12, and is trivially triggerable from the network with no user interaction given network access to the management/websocket interface. Successful exploitation gives full super-admin control of the appliance, which attackers can use to pivot, create persistent access, and deploy ransomware. Any organization running the affected FortiOS or FortiProxy versions, especially with admin interfaces reachable from the internet, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-01-14, and multiple ransomware crews (reported as Gunra, SuperBlack, and Mora_001) are actively exploiting it. Do: Upgrade all affected systems beyond the vulnerable ranges — FortiOS later than 7.0.16 and FortiProxy later than 7.0.19 / 7.2.12 — following Fortinet's advisory, or apply the vendor's mitigations where upgrades are not possible (per CISA KEV instructions). Restrict access to the admin/websocket interface from the internet, and hunt for unauthorized super-admin accounts and suspicious websocket connections, since ransomware operators are actively exploiting this flaw. Verify device versions and audit logs for signs of compromise before and after patching. | 9.8 | 98% | KEV ransomware |
| large≈48,000+ internet-exposed Fortinet devices per public scans, out of an installed base in the hundreds of thousands | |
| CVE-2025-24472 | Authentication Bypass in Fortinet FortiOS and FortiProxy Grants Super-Admin Access CVE-2025-24472 is an authentication bypass (CWE-288) in the Fortinet Security Fabric of FortiOS and FortiProxy. A remote, unauthenticated attacker who already knows the serial numbers of both the upstream and downstream devices can send crafted CSF proxy requests to gain super-admin privileges on the downstream device; the attack only works where the Security Fabric is enabled, and the need for serial-number knowledge raises attack complexity. An attacker gains full super-admin control of the downstream Fortinet device, which can serve as a foothold for network-wide compromise. Organizations running affected FortiOS 7.0.x or FortiProxy 7.0.x/7.2.x builds with Security Fabric enabled are in scope. The flaw was added to CISA's KEV catalog on 2025-03-18 with known ransomware use, and multiple ransomware groups (including Gunra, SuperBlack, Mora_001 and Qilin operators) have been reported exploiting Fortinet firewall flaws in recent campaigns. Do: Upgrade FortiOS 7.0.x and FortiProxy 7.0.x/7.2.x deployments to the fixed releases listed in the Fortinet PSIRT advisory for CVE-2025-24472, and identify any devices where the Security Fabric is enabled and serial numbers of peer devices may be discoverable. As interim mitigation, restrict or disable Security Fabric (CSF) connectivity toward untrusted peers and limit access to the CSF proxy handling path. Because the flaw is KEV-listed with known ransomware use, federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use, and all defenders should review device logs for unexpected super-admin sessions and anomalous CSF proxy traffic. | 8.1 | 7% | KEV ransomware |
| masshundreds of thousands of deployed Fortinet appliances plausibly affected; the practical subset is those with Security Fabric enabled |
Full article742 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 24, 2025Malware / Ransomware
A ransomware-as-a-service (RaaS) operation called VanHelsing has already claimed three victims since it launched on March 7, 2025, demanding ransoms as high as $500,000.
"The RaaS model allows a wide range of participants, from experienced hackers to newcomers, to get involved with a $5,000 deposit. Affiliates keep 80% of the ransom payments, while the core operators earn 20%," Check Point said in a report published over the weekend.
"The only rule is not to target the Commonwealth of Independent States (CIS)."
As with any affiliate-backed ransomware program, VanHelsing claims to offer the ability to target a wide range of operating systems, including Windows, Linux, BSD, Arm, and ESXi. It also employs what's called the double extortion model of stealing data prior to encryption and threatening to leak the information unless the victim pays up.
The RaaS operators have also revealed that the scheme offers a control panel that works "seamlessly" on both desktop and mobile devices, with even support for dark mode.
What makes VanHelsing notable is that it allows reputable affiliates to join for free, while new affiliates are required to pay a $5,000 deposit in order to gain access to the program.
Once launched, the C++-based ransomware takes steps to delete shadow copies, enumerate local and network drives, and encrypt files with the extension ".vanhelsing," after which the desktop wallpaper is modified, and a ransom note is dropped onto the victim system, urging them to make a Bitcoin payment.
It also supports various command-line arguments to dictate various aspects of the ransomware's behavior, such as the encryption mode to be used, the locations that need to be encrypted, spread the locker to SMB servers, and skip renaming the files with the ransomware extension in "Silent" mode.
According to CYFIRMA, government, manufacturing, and pharmaceutical companies located in France and the United States have become the targets of the nascent ransomware operation.
"With a user-friendly control panel and frequent updates, VanHelsing is becoming a powerful tool for cybercriminals," Check Point said. Within just two weeks of its launch, it has already caused significant damage, infecting multiple victims and demanding hefty ransoms.
The emergence of VanHelsing coincides with a number of developments in the ever-evolving ransomware landscape -
- The discovery of new versions of Albabat ransomware that go beyond Windows to Linux and macOS, gathering system and hardware information
- BlackLock ransomware, a rebranded version of Eldorado, has become one of the most active RaaS groups in 2025, targeting technology, manufacturing, construction, finance, and retail sectors
- BlackLock is actively recruiting traffers to drive early stages of ransomware attacks, directing victims to malicious pages that deploy malware capable of establishing initial access to compromised systems
- The JavaScript-based malware framework known as SocGholish (aka FakeUpdates) is being used to deliver RansomHub ransomware, an activity attributed to a threat cluster dubbed Water Scylla
- The exploitation of security flaws in Fortinet firewall appliances (CVE-2024-55591 and CVE-2025-24472) by a threat actor dubbed Mora_001 since late January 2025 to deliver a newly discovered ransomware strain codenamed SuperBlack, a modified version of LockBit 3.0 that utilizes a custom data exfiltration tool
- The Babuk2 (aka Babuk-Bjorka) ransomware group has been observed reusing data from earlier breaches associated with RansomHub, FunkSec, LockBit, and Babuk to issue fake extortion demands to victims
According to statistics compiled by Bitdefender, February 2025 was the worst month for ransomware in history, hitting a record 962 victims, up from 425 victims in February 2024. Of the 962 victims, 335 have been claimed by the Cl0p RaaS group.
Another notable trend is the increase in remote encryption attacks, wherein ransomware attackers compromise an unmanaged endpoint, and leverage that access to encrypt data on managed, domain-joined machines.
Telemetry data shared by Sophos reveals that there has been a surge in remote encryption by 50% year-on-year in 2024, and a 141% rise since 2022.
"Remote encryption has now become a standard part of ransomware groups' bag of tricks," said Chester Wisniewski, director and global field CISO at Sophos. "Every organization has blind spots and ransomware criminals are quick to exploit weaknesses once discovered."
"Increasingly the criminals are seeking out these dark corners and using them as camouflage. Businesses need to be hypervigilant in ensuring visibility across their entire estate and actively monitor any suspicious file activity."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/03/vanhelsing-raas-launch-3-victims-5k.html