
VantaCore Deploys Custom Encryptor, Loader, RAT and AV-Killer Against Russian Targets
VantaCore marks the latest iteration of Ukrainian-aligned ransomware actors moving to fully custom stacks. The F6 report supplies the clearest technical trail yet, but lacks independent confirmation of political versus purely financial motives. Continued custom development will complicate both detection and any future attribution claims.
F6 traced the group’s Tor leak site to June and linked its TTPs to the earlier Thor operation that claimed twelve victims in 2025. Initial access relied on exposed VPNs, internet-facing application flaws and stolen partner credentials; once inside, the custom loader pushed the encryptor across servers and endpoints while SnowKiller disabled AV products. The shift away from LockBit and Babuk coincides with documented weaknesses in those families and explicit reluctance among pro-Ukrainian operators to run Russian-origin code.
Contract awards and procurement records show Ukrainian-aligned groups have steadily moved from commodity ransomware to bespoke tooling throughout 2025-2026. F6 notes VantaCore still follows standard RaaS affiliate patterns yet retains the option to repurpose stolen data for non-financial operations, a pattern previously observed when Thor mixed extortion with disruptive activity. No independent technical attribution to any state entity has surfaced; the evidence remains limited to malware signatures, infrastructure reuse and victim geography.
Russian firms face elevated risk of secondary data sales or follow-on targeting once initial extortion fails. Continued custom-tool development will raise the bar for detection signatures and increase the likelihood that compromised Russian networks become staging points for further regional operations. Monitoring for new SnowKiller variants and Tor leak-site updates provides the clearest early indicators.
Procurement patterns suggest the broader reorganization of pro-Ukrainian crews will accelerate through 2026 as groups seek to reduce dependence on shared Russian malware.
SENTINEL: VantaCore will publish data from at least two additional Russian victims on its Tor site before 31 March 2026.
Sources (3)
- [1]F6 VantaCore Technical Report(https://f6.ru/research/vantacore-2025)
- [2]The Record Coverage(https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia)
- [3]Recorded Future 2025 Pro-Ukraine Ransomware Trends(https://recordedfuture.com/reports/pro-ukraine-ransomware-2025)