VantaCore Ransomware Group Targets Russian Firms in Pro-Ukraine Campaign
A ransomware operation believed to be linked to pro-Ukrainian hacktivists is targeting Russian organizations with bespoke malware and multimillion-dollar ransom demands. Researchers at Russian cybersecurity firm F6 identified the operators as VantaCore, a group that has claimed at least seven victims since first surfacing in August 2025. A data-leak site tied to the group was registered in early June. F6 assesses with high confidence that VantaCore is a rebrand of Thor, a prolific pro-Ukrainian ransomware actor responsible for at least 12 attacks against domestic Russian targets during 2025. Unlike its predecessor, which blended financial extortion with politically motivated disruption, VantaCore appears primarily profit-driven, operating as a ransomware-as-a-service (RaaS) business that leases its toolkit to vetted affiliates. Victims negotiate through a Tor-based chat portal, and stolen data is published on the group's leak site when ransoms go unpaid.
The group's initial-access tradecraft is consistent with mainstream ransomware affiliates rather than elite nation-state operators. F6 reports that VantaCore actors routinely exploit poorly hardened remote-access infrastructure, including VPN and proxy endpoints exposed without multi-factor authentication, alongside n-day vulnerabilities in internet-facing applications such as webmail and VPN concentrators. Operators also rely on credential theft, leveraging stealer logs and credentials harvested from compromised business partners to pivot into victim environments. Organizations should audit remote-access exposure and validate that perimeter services are not leaking configuration data, which can be confirmed through a port scanner to identify rogue services and shadow IT.
What distinguishes VantaCore from commodity RaaS operations is its reliance on a purpose-built toolchain. The flagship payload, also named VantaCore, is a cross-platform encryptor capable of locking files on both Windows servers and employee endpoints. Distribution is handled by VantaCoreLoader, which stages the ransomware across compromised networks, while VantaCoreRAT provides persistent remote access for reconnaissance, file transfer, and command execution. A fourth utility called SnowKiller is deployed to disable endpoint detection and antivirus products before encryption begins. "Their tactics, techniques and procedures are largely effective, although they are neither sophisticated nor innovative," F6 noted. Defenders should prioritize EDR tamper protection and credential hygiene; reviewing exposed passwords through a password strength checker is a practical first step for security teams.
VantaCore's emergence is part of a broader restructuring of pro-Ukrainian cyber-actor collectives observed by F6 throughout 2025 and into 2026. Researchers have documented several affiliated groups migrating away from leaked or publicly available ransomware strains such as LockBit 3 Black and Babuk in favor of proprietary malware, reducing forensic overlap with Western-tracked operations. Beyond financial extortion, data exfiltrated by these groups is frequently republished or auctioned to other pro-Ukrainian actors for use in follow-on intrusions, influence operations, and targeted attacks against Russian individuals. The shift underscores how the cyber dimension of the Russia-Ukraine conflict continues to professionalize, with hybrid financially motivated and politically aligned operations becoming the new norm.