VectraRAT: Undocumented $250/Month Full-Stack Malware-as-a-Service With UAC Bypass and Crypto-Clipboard Hijacking
SOCRadar documented VectraRAT, a from-scratch, rental-only Malware-as-a-Service platform sold for $250/month under the aliases Vectra (formerly Nyxel), pairing a Go-based VectraHub Linux C2 with a C++ Windows implant; it bypasses UAC via UACME method 41,…
SOCRadar's Threat Research Unit (STRU) documented VectraRAT, a previously undocumented, rental-only Malware-as-a-Service platform built entirely from scratch rather than forked from leaked builders, sold by a developer known as Vectra (formerly Nyxel). The discovery followed an exposed online directory that revealed samples, licenses, and operator logs across ten-plus servers. The toolkit offered to affiliates includes a Go-based VectraHub Linux C2 server embedding a Vue3 operator panel, a C++ Windows implant, a payload builder, and support, rented from $250/month. Per GBHackers, the implant communicates over TCP port 3308 via a proprietary MessagePack protocol (Cyber Security News more generally describes custom TCP-based C2 over non-standard ports). On connect it steals Chromium, Firefox, and Internet Explorer credentials and hunts .env, .conf, and .config files for API keys, cloud secrets, and database strings. Capabilities include hidden VNC desktop sessions, keylogging, command execution, file transfer, SOCKS5 proxying, and regex-based clipboard replacement of crypto wallet addresses to support fraud; the callback address can be changed post-install, complicating blocking. Privilege escalation is silent, abusing UACME method 41 by hijacking a debug object from winver.exe to launch elevated computerdefaults.exe without a prompt. Distribution occurs through the Amadey loader and ClickFix pages impersonating TurboTax, which instruct users to paste commands into Run or PowerShell. SOCRadar recorded 38 genuine victim sessions — described as within one week by GBHackers and under a week by Cyber Security News — with 48% of victims with OS data running corporate Windows editions; victims were concentrated in the US, Russia, and Germany, and one Windows Server 2025 host showed rapid data theft activity. Defenders are urged to watch for PowerShell spawned after clipboard writes.
- VectraRAT is a previously undocumented, rental-only Malware-as-a-Service platform built entirely from scratch, not forked from leaked builders; linked to the aliases Vectra (formerly Nyxel).
- Rental from $250/month includes a Linux control server, Windows implant, payload builder, and support.
- An exposed online directory revealed samples, licenses, and operator logs across ten-plus servers.
- Architecture: Go-based VectraHub Linux C2 server embedding a Vue3 operator panel, plus a C++ Windows implant.
- C2 communication: TCP port 3308 via a proprietary MessagePack protocol (GBHackers); Cyber Security News describes custom TCP-based C2 over non-standard ports.
- Implant steals Chromium, Firefox, and IE credentials and hunts .env, .conf, and .config files for API keys, cloud secrets, and database strings.
- Capabilities include hidden VNC sessions, keylogging, command execution, file transfer, SOCKS5 proxying, and regex clipboard replacement of crypto wallet addresses.
- UAC bypass abuses UACME method 41, hijacking a debug object from winver.exe to launch elevated computerdefaults.exe without a prompt.
Coverage timelineoldest first · each row is one article
- · 2d agoVectraRAT: An Undocumented Full-Stack MaaS Built From Scratch
SOCRadar· 55
SOCRadar's Threat Research Unit documents VectraRAT, a previously unreported full-stack Malware-as-a-Service platform built entirely from scratch.
- · 3h agoVectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
GBHackers· 58
New VectraRAT malware-as-a-service at $250/month combines RAT capabilities, credential theft, clipboard hijacking, and a UACME-based UAC bypass; 38 victims observed.
- · 1h agoHackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs
Cyber Security News· 58
SOCRadar uncovered VectraRAT, a previously undocumented $250-per-month Windows RAT rental service delivered via Amadey and ClickFix lures.