VantaCore ransomware group targets Russian
A pro-Ukraine ransomware group named VantaCore is using custom malware to extort millions from Russian organizations, according to research from

A new ransomware group, VantaCore, is targeting Russian companies with custom-built malware and demanding multi-million dollar ransoms. Russian cybersecurity firm F6 detailed the group's activities in a report published this week, stating it first detected the operation in August, though the associated data-leak site was created in early June.
F6 researchers believe this entity is a rebrand of Thor, a pro-Ukrainian hacking group that was active against Russian targets last year. The firm attributed at least 12 attacks to Thor in 2025. While Thor's operations mixed financial crime with politically motivated disruption, F6 assesses that the new group appears primarily focused on financial gain.
Tactics and custom toolset
The threat actors operate on a ransomware-as-a-service (RaaS) model, providing malware and infrastructure to affiliates who execute attacks. They use common initial access methods, including exploiting poorly secured VPNs and remote-access tools, vulnerabilities in internet-facing applications, and stolen partner credentials.
"Their tactics, techniques and procedures are largely effective, although they are neither sophisticated nor innovative," F6 said in its report.
What distinguishes the operation is its reliance on a suite of proprietary hacking tools. The core component is its custom ransomware, which can encrypt data on both servers and employee workstations.
Proprietary malware arsenal
To deploy its ransomware, the group uses a custom loader and a remote access trojan (RAT). These tools allow the attackers to move laterally through a compromised network and maintain persistent control.
Another tool, SnowKiller, is designed specifically to disable security software on infected systems. This arsenal enables a comprehensive attack chain from initial intrusion to data encryption and extortion.
Data exploitation and group evolution
F6 noted that, like other pro-Ukrainian groups, the hackers may use stolen data for purposes beyond simple extortion. Information taken from Russian organizations could be published or sold online, and potentially used in further cyberattacks or operations against Russian entities.
The emergence of this group is part of a broader reorganization observed among pro-Ukrainian hacking groups during 2025 and 2026. Researchers have seen a shift away from widely available ransomware strains like LockBit 3 Black and Babuk towards custom-built malware.
F6 suggests this shift is driven by discovered weaknesses in those existing tools and a reluctance among pro-Ukrainian hackers to rely on software with Russian origins. The threat actors communicate with victims via a Tor-based chat service and maintain a leak site to publish stolen data, applying pressure for ransom payments.





