New pro-Ukraine hacker group targets Russian companies with custom ransomware
F6 links new pro-Ukraine ransomware group VantaCore, likely a Thor rebrand, to seven attacks on Russian firms using custom tooling and multimillion-dollar demands.
Russian cybersecurity firm F6 reports that VantaCore, a ransomware group believed to be a rebrand of pro-Ukrainian group Thor, has targeted at least seven Russian organizations with ransom demands reaching millions of dollars, operating as a ransomware-as-a-service operation with a Tor-based victim chat and a leak site. The group uses custom-built tooling including the VantaCore ransomware that encrypts servers and workstations, VantaCoreLoader for distribution, the VantaCoreRAT backdoor, and SnowKiller, which disables antivirus and security software. Initial access relies on poorly secured VPNs and remote-access tools, flaws in internet-facing applications, and credentials stolen from business partners. F6 notes pro-Ukrainian groups increasingly abandoned stock ransomware like LockBit 3 Black and Babuk in 2025-2026 in favor of custom malware.
- Believed to be a rebrand of Thor, which F6 attributed at least 12 attacks to in 2025
- Custom stack: VantaCore ransomware, VantaCoreLoader, VantaCoreRAT backdoor, and SnowKiller defense-impairment tool
- Gains access via weak VPNs, internet-facing app flaws, and stolen partner credentials; communicates via Tor chat and leak site
- Broader trend of pro-Ukrainian groups building custom ransomware instead of using LockBit 3 Black or Babuk
Full article504 words · extracted from therecord.media · click to collapse
A ransomware group believed to be linked to pro-Ukrainian hackers is targeting Russian organizations with custom malware and demanding multimillion-dollar payments, according to new research. The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week. Researchers first detected its activity in August, although the group's data-leak website appears to have been created in early June. Researchers said they believe VantaCore is a rebrand of Thor, a pro-Ukrainian hacking group that was among the more active ransomware operations targeting Russia last year. F6 attributed at least 12 attacks to Thor in 2025. Its operations have combined financial extortion with destructive or politically motivated activity, according to the company. VantaCore, however, appears primarily focused on making money, according to F6, with ransom demands reaching millions of dollars. The group operates as a ransomware-as-a-service operation, a business model in which ransomware developers provide malware and infrastructure to affiliates who carry out attacks. VantaCore communicates with victims through a Tor-based chat service and maintains a leak site where stolen information can be published. The hackers use several common methods to break into corporate networks, including exploiting poorly secured VPNs and other remote-access tools, flaws in internet-facing applications and login credentials stolen from business partners. “Their tactics, techniques and procedures are largely effective, although they are neither sophisticated nor innovative,” F6 said. What sets VantaCore apart from many ransomware operations is its reliance on a collection of custom-built hacking tools. F6 said it detected attacks in August involving the group's proprietary ransomware, also called VantaCore, which can encrypt data on both servers and employees' computers. The attackers use another custom tool, VantaCoreLoader, to distribute the ransomware and other malicious software throughout compromised networks. They also deploy VantaCoreRAT, a backdoor that can gather information about infected systems, transfer files and remotely execute commands. Another tool, dubbed SnowKiller, is designed to disable security software, including antivirus products. Like other pro-Ukrainian hacking groups, VantaCore may use stolen data for more than just extortion, F6 said. Information taken from Russian organizations can be published or sold online and potentially used in further cyberattacks or other operations targeting Russian companies and individuals. The emergence of VantaCore comes amid a broader reorganization of pro-Ukrainian hacking groups that F6 said it observed during 2025 and 2026. Researchers have seen some of these groups stop using widely available ransomware such as LockBit 3 Black and Babuk and instead build their own malware. F6 said the shift is partly driven by weaknesses found in those ransomware tools over time, as well as reluctance among pro-Ukrainian hackers to rely on software with Russian roots.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia