HabrAugust 31, 2026🇷🇺Translated from Russian

Ragnarök: F6 Investigates VantaCore Ransomware Attacks and Suspected Thor Rebrand

Specialists from F6’s Laboratory of Digital Forensics and Malware Research have reported a new threat to Russian businesses. In August 2026 the laboratory detected activity from a ransomware group calling itself VantaCore. The confirmed number of victims stands at no fewer than seven, with ransom demands reaching millions of dollars.

Researchers believe VantaCore is a rebrand of the previously known pro-Ukrainian group Thor. F6 has previously documented consolidation and regrouping among pro-Ukrainian collectives during 2025–2026. A parallel trend is the abandonment of LockBit 3 Black and Babuk in favor of custom encryptors. In March 2026 F6 reported that Bearlyfy had switched to its own GenieLocker ransomware; in August the same pattern appeared with VantaCore.

Reasons for dropping LockBit 3 Black and Babuk include their Russian origins and accumulated technical shortcomings. Nevertheless, the new encryptors retain code and design similarities with both families. VantaCore also launched a data-leak site in June 2026 and positioned itself as a professional Ransomware-as-a-Service operation, complete with a Tor chat for victim negotiations.

The group employs double and triple extortion. After encryption, stolen data is sold or published on its leak site and later reused for further attacks against Russian entities. Initial access vectors include poorly secured RDP and VPN services, vulnerabilities in public-facing applications, and compromised partner credentials.

Once inside the network, operators move laterally using harvested legitimate accounts over SMB and RDP. They perform reconnaissance with both custom scanners and native utilities such as ping, netsh, quser, qwinsta and net user. Persistence is achieved through newly created Windows services, while remote access is provided by the legitimate Tactical RMM tool and the custom VantaCoreRAT backdoor written in Go.

To remain undetected, the attackers obfuscate binaries, delete tools and logs after use, clear Windows event logs with PowerShell and wevtutil, and disable security products manually or via the SnowKiller BYOVD utility. Backups are destroyed by overwriting RAID arrays with arbitrary data using the open-source Bootice utility.

Encryption is performed by the custom VantaCore ransomware developed in C++. The binary accepts a hardcoded password on the command line and uses ChaCha20 with X25519 for file encryption. Mass deployment is handled by the custom VantaCoreLoader tool, which spreads via administrative shares in a manner similar to LockBit 3 Black’s psexec_netspread module.

Related articles

BoletimSecRansomware & Extortion

Ransomware Operators Linked to The Gentlemen Deploy TukTuk C2 Framework for Espionage and Credential Theft

Operators associated with the ransomware group The Gentlemen have adopted a new command-and-control framework called TukTuk to steal credentials, monitor compromised systems, and prepare environments for ransomware deployment. The framework was discovered on a server that also hosted tools for disabling EDR solutions, research on vulnerable drivers, and data apparently stolen from two large organizations. TukTuk includes agents for both Windows and Linux, along with its own backend and management panel that allows remote command execution, file transfers, screen capture, and device tracking through a single interface. One notable feature displays a fake Windows Security window on the victim's machine to capture entered credentials and send them directly to the attackers' panel. Researchers identified a DLL sideloading technique that abuses the legitimate Greenshot.exe executable to load a malicious log4net.dll library and launch the TukTuk agent. The server also contained EDRKiller, WarsawKiller, and UnknownKiller tools, plus materials on BYOVD attacks that leverage vulnerable legitimate drivers to gain kernel access and interfere with security products.

SecuritylabRansomware & Extortion

The Evolution of Ransomware: From 1989 Floppy Disks to Multi-Million Dollar Extortion Empires

Ransomware has transformed dramatically since its origins in 1989, when evolutionary biologist Joseph Popp mailed AIDS-themed floppy disks demanding $189 via Panamanian mail. Early experiments like GPCode and Archiveus introduced stronger cryptography by the mid-2000s, while Reveton and CryptoLocker in 2012-2013 combined psychological pressure, Gameover Zeus botnets, and Bitcoin payments. Major incidents such as WannaCry, NotPetya, and attacks on Colonial Pipeline and JBS Foods demonstrated global reach and state-level involvement. Modern groups like REvil, LockBit, Maze, and Akira refined double extortion, Ransomware-as-a-Service models, access brokers, and virtualization targeting. Law enforcement operations have disrupted infrastructure repeatedly, yet the market fragments and regenerates with new brands. The core business model remains resilient due to easy initial access, layered extortion tactics, and victims' operational dependencies.

BoletimSecRansomware & Extortion

Ransomware Group TITAN Deploys Local AI on AMD EPYC Servers to Accelerate Stolen Data Analysis

The TITAN ransomware group has announced the integration of an on-premises artificial intelligence platform designed to process up to 700 GB of exfiltrated data per hour. Operating as a ransomware-as-a-service model since May 2026, TITAN combines file encryption with data theft and has already published 24 victims across 10 countries. Manufacturing and professional services firms account for 29 percent of the targeted organizations. The AI system runs locally on AMD EPYC servers with GPU acceleration and automatically classifies financial documents, legal records, personal data, trade secrets, and intellectual property. It further identifies information with high reputational or regulatory impact, maps corporate and personal relationships, and estimates potential penalties under data-protection laws. The group also claims the platform can generate automated notifications to regulators and media outlets to intensify extortion pressure.

AntiMalwareRansomware & Extortion

VantaCore Ransomware Group Targets Russian Businesses with Custom Toolkit and Triple Extortion

Security researchers at F6 have identified a new ransomware operation called VantaCore that is actively attacking small and medium-sized Russian companies. The group employs a custom set of tools including VantaCoreLoader, VantaCoreRAT, and its own encryption malware to conduct double and triple extortion campaigns. Initial access is gained through poorly secured RDP and VPN services, vulnerable public applications, and compromised partner accounts. Once inside the network, attackers move laterally using SMB and RDP with legitimate credentials, deploy Tactical RMM, and install their backdoor before disabling security products with an AV/EDR killer. Victims face data theft, backup destruction, and encryption, followed by threats to publish or sell stolen information if ransom demands in the millions of dollars are not met. F6 assesses that VantaCore may be a rebranded version of the previously known pro-Ukrainian group Thor, based on similar Tor negotiation chat design and a THOR rune icon on the leak site that appeared no later than June 7, 2026.