ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

VectraRAT: Undocumented $250/Month Full-Stack Malware-as-a-Service With UAC Bypass and Crypto-Clipboard Hijacking

mediumMalwareexploited in the wildimportance 58
What's new: Report 3 (Cyber Security News) adds material beyond the previous summary: the discovery originated from an exposed online directory revealing samples, licenses, and operator logs across ten-plus servers; the rental model is described as rental-only and includes a payload builder and support; added capabilities include command execution and file transfer; ClickFix lures explicitly instruct users…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

SOCRadar documented VectraRAT, a from-scratch, rental-only Malware-as-a-Service platform sold for $250/month under the aliases Vectra (formerly Nyxel), pairing a Go-based VectraHub Linux C2 with a C++ Windows implant; it bypasses UAC via UACME method 41,…

SOCRadar's Threat Research Unit (STRU) documented VectraRAT, a previously undocumented, rental-only Malware-as-a-Service platform built entirely from scratch rather than forked from leaked builders, sold by a developer known as Vectra (formerly Nyxel). The discovery followed an exposed online directory that revealed samples, licenses, and operator logs across ten-plus servers. The toolkit offered to affiliates includes a Go-based VectraHub Linux C2 server embedding a Vue3 operator panel, a C++ Windows implant, a payload builder, and support, rented from $250/month. Per GBHackers, the implant communicates over TCP port 3308 via a proprietary MessagePack protocol (Cyber Security News more generally describes custom TCP-based C2 over non-standard ports). On connect it steals Chromium, Firefox, and Internet Explorer credentials and hunts .env, .conf, and .config files for API keys, cloud secrets, and database strings. Capabilities include hidden VNC desktop sessions, keylogging, command execution, file transfer, SOCKS5 proxying, and regex-based clipboard replacement of crypto wallet addresses to support fraud; the callback address can be changed post-install, complicating blocking. Privilege escalation is silent, abusing UACME method 41 by hijacking a debug object from winver.exe to launch elevated computerdefaults.exe without a prompt. Distribution occurs through the Amadey loader and ClickFix pages impersonating TurboTax, which instruct users to paste commands into Run or PowerShell. SOCRadar recorded 38 genuine victim sessions — described as within one week by GBHackers and under a week by Cyber Security News — with 48% of victims with OS data running corporate Windows editions; victims were concentrated in the US, Russia, and Germany, and one Windows Server 2025 host showed rapid data theft activity. Defenders are urged to watch for PowerShell spawned after clipboard writes.

  • VectraRAT is a previously undocumented, rental-only Malware-as-a-Service platform built entirely from scratch, not forked from leaked builders; linked to the aliases Vectra (formerly Nyxel).
  • Rental from $250/month includes a Linux control server, Windows implant, payload builder, and support.
  • An exposed online directory revealed samples, licenses, and operator logs across ten-plus servers.
  • Architecture: Go-based VectraHub Linux C2 server embedding a Vue3 operator panel, plus a C++ Windows implant.
  • C2 communication: TCP port 3308 via a proprietary MessagePack protocol (GBHackers); Cyber Security News describes custom TCP-based C2 over non-standard ports.
  • Implant steals Chromium, Firefox, and IE credentials and hunts .env, .conf, and .config files for API keys, cloud secrets, and database strings.
  • Capabilities include hidden VNC sessions, keylogging, command execution, file transfer, SOCKS5 proxying, and regex clipboard replacement of crypto wallet addresses.
  • UAC bypass abuses UACME method 41, hijacking a debug object from winver.exe to launch elevated computerdefaults.exe without a prompt.

Coverage timeline

  1. · 2d ago
    SOCRadar· 55
    VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch

    SOCRadar's Threat Research Unit documents VectraRAT, a previously unreported full-stack Malware-as-a-Service platform built entirely from scratch.

  2. · 3h ago
    GBHackers· 58
    VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems

    New VectraRAT malware-as-a-service at $250/month combines RAT capabilities, credential theft, clipboard hijacking, and a UACME-based UAC bypass; 38 victims observed.

  3. · 1h ago
    Cyber Security News· 58
    Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs

    SOCRadar uncovered VectraRAT, a previously undocumented $250-per-month Windows RAT rental service delivered via Amadey and ClickFix lures.