VantaCore Ransomware Group Targets Russian Businesses with Custom Toolkit and Triple Extortion
Specialists at F6 have discovered a new ransomware group operating under the name VantaCore that is targeting Russian small and medium-sized businesses with its own suite of malicious tools. At least four victims have already been identified, with ransom demands reaching millions of dollars.
According to F6, VantaCore may represent a new branding of the previously known pro-Ukrainian group Thor. Evidence includes a similar design of Tor-based negotiation chats and a site icon featuring the runic inscription THOR. The leak resource itself appeared no later than June 7, 2026.
The attackers employ double and triple extortion tactics. They first steal data, then destroy backups and encrypt critical information. If the company refuses to pay, the stolen materials are published, sold, or used in follow-on attacks.
Initial access is achieved by targeting weakly protected RDP and VPN services, vulnerable public-facing applications, and compromised partner credentials. Inside the network, the group moves laterally via SMB and RDP using legitimate accounts.
On compromised Windows systems, the attackers create services, install Tactical RMM, and deploy their custom backdoor VantaCoreRAT. Mass deployment of tools is handled by the proprietary loader VantaCoreLoader.
Before launching the encryptor, the criminals stop protective processes using an AV/EDR killer and then deploy the VantaCore ransomware across servers and workstations. Negotiations occur through a Tor chat whose link is provided in the ransom note.
While the attack techniques themselves are not considered particularly sophisticated by F6, the group’s fully custom toolset and well-established pressure tactics make the operation effective against its targets.
Related articles
Boston Scientific Hit by Cyber Attack: Global IT Outage Disrupts Orders and Shipments, Shares Drop
On August 25, Boston Scientific detected a cyber attack that compromised parts of its IT infrastructure, leading to widespread network interruptions across its global operations. The medical device giant, which generates over $16 billion in annual revenue and operates in more than 130 countries, saw customer order processing and product shipments halted in multiple regions. Wall Street Journal and Reuters reported the incident on August 26, after which the company's stock declined. While China operations remained unaffected due to regional system isolation, the company stated that full global recovery timelines remain unknown. The attack's specific methods, including any potential ransomware involvement or data exfiltration, have not been disclosed as third-party investigators continue their work. The event underscores the severe operational and patient-care risks when healthcare supply chains face cyber disruptions.
Aurora Ransomware Affiliate Uses AI Assistant Cursor to Compromise Active Directory and VMware ESXi Servers
An affiliate of the Aurora ransomware group employed the AI-powered coding assistant Cursor to plan and execute targeted attacks against corporate environments, focusing on Active Directory and VMware ESXi servers. The campaign impacted more than 20 organizations between April and July 2026. The operator used Cursor to generate commands, refine exploitation techniques, and build attack sequences aimed at Windows infrastructure, particularly Active Directory Certificate Services (ADCS). Techniques included noPac exploitation combined with NTLM relay attacks leveraging PetitPotam, PrinterBug, and DFSCoerce to escalate privileges up to domain administrator level. After gaining access, the attackers collected and compressed large volumes of data for exfiltration before deploying the Aurora ransomware on Windows, Linux, and ESXi systems. The ESXi variant stops virtual machines prior to encryption to maximize impact on virtualized environments.
7 Core Rules for Responding to Ransomware and Infrastructure Breaches
The article outlines practical first-response steps for organizations facing ransomware encryption or infrastructure compromise for the first time. It stresses isolating affected systems from the network without powering them down, preserving volatile data and logs, and avoiding premature cleanup or backup restoration. The guidance covers closing obvious compromised access paths, documenting observed facts and actions, and stopping further ad-hoc changes once containment is achieved. These measures help retain forensic artifacts that investigators need to determine the initial access vector and attacker movement. The rules are presented as a starting point for teams without formal incident response procedures.
IT Elements 2026 to Stage IT Apocalypse Simulations and Critique Russian Vendors
The IT Elements 2026 conference has unveiled its full program, centering on business continuity after successful cyberattacks, infrastructure failures, or technological disasters. Scheduled for September 9-10 at the Serp i Molot cultural center in Moscow, the event will host over one hundred reports, discussions, demonstrations, and master classes. The opening plenary will examine whether the primary-backup data center model remains viable, if the 3-2-1 backup rule still protects against modern ransomware, and whether CIOs or CISOs should own cyber resilience. Practical sessions will demonstrate a full Microsoft migration in 60 minutes, moving Exchange and MinIO to Russian alternatives, and a detailed review of domestic hyperconvergence strengths and weaknesses. Comparative test results for routers, NGFW, and VM systems will be presented without marketing gloss. Additional tracks will cover monitoring of corporate AI models from GPU to prompt under FSTEC Order No. 117, OWASP Top 10 for LLM, and MITRE ATLAS, alongside real-world cases from Rosatom, Beeline, Sber, and T-Bank. Trubnaya Metallurgicheskaya Kompaniya will simulate a 48-hour IT outage and show how to restart operations in half a day.