HabrAugust 31, 2026🇷🇺Translated from Russian

Ragnarök: F6 Investigates VantaCore Ransomware Attacks and Suspected Thor Rebrand

Specialists from F6’s Laboratory of Digital Forensics and Malware Research have reported a new threat to Russian businesses. In August 2026 the laboratory detected activity from a ransomware group calling itself VantaCore. The confirmed number of victims stands at no fewer than seven, with ransom demands reaching millions of dollars.

Researchers believe VantaCore is a rebrand of the previously known pro-Ukrainian group Thor. F6 has previously documented consolidation and regrouping among pro-Ukrainian collectives during 2025–2026. A parallel trend is the abandonment of LockBit 3 Black and Babuk in favor of custom encryptors. In March 2026 F6 reported that Bearlyfy had switched to its own GenieLocker ransomware; in August the same pattern appeared with VantaCore.

Reasons for dropping LockBit 3 Black and Babuk include their Russian origins and accumulated technical shortcomings. Nevertheless, the new encryptors retain code and design similarities with both families. VantaCore also launched a data-leak site in June 2026 and positioned itself as a professional Ransomware-as-a-Service operation, complete with a Tor chat for victim negotiations.

The group employs double and triple extortion. After encryption, stolen data is sold or published on its leak site and later reused for further attacks against Russian entities. Initial access vectors include poorly secured RDP and VPN services, vulnerabilities in public-facing applications, and compromised partner credentials.

Once inside the network, operators move laterally using harvested legitimate accounts over SMB and RDP. They perform reconnaissance with both custom scanners and native utilities such as ping, netsh, quser, qwinsta and net user. Persistence is achieved through newly created Windows services, while remote access is provided by the legitimate Tactical RMM tool and the custom VantaCoreRAT backdoor written in Go.

To remain undetected, the attackers obfuscate binaries, delete tools and logs after use, clear Windows event logs with PowerShell and wevtutil, and disable security products manually or via the SnowKiller BYOVD utility. Backups are destroyed by overwriting RAID arrays with arbitrary data using the open-source Bootice utility.

Encryption is performed by the custom VantaCore ransomware developed in C++. The binary accepts a hardcoded password on the command line and uses ChaCha20 with X25519 for file encryption. Mass deployment is handled by the custom VantaCoreLoader tool, which spreads via administrative shares in a manner similar to LockBit 3 Black’s psexec_netspread module.

Related articles

AntiMalwareRansomware & Extortion

Ukrainian Developer of LockerGoga, MegaCortex and Nefilim Ransomware Sentenced to 12 Years and Nine Months

A 52-year-old Ukrainian national has been sentenced by the Zurich District Court to 12 years and nine months in prison for his role as the lead developer of the LockerGoga, MegaCortex and Nefilim ransomware strains. The court determined that the malware he created was deployed against companies across dozens of countries, causing approximately 100 million Swiss francs in damages in the cases examined. Notable victims included train manufacturer Stadler Rail, which suffered the theft of around 500 GB of confidential data and a $6 million ransom demand in 2020, as well as climate equipment supplier Meier Tobler and banking software developer Crealogix. The defendant claimed he was performing ordinary cybersecurity consulting and was unaware of the intended use of his code, but investigators found ransom demand templates alongside the source code, undermining his defense. He has been in custody since October 2021 as part of a wider international investigation into attacks affecting more than 1,800 individuals and organizations in 71 countries. Upon release he will be banned from entering Switzerland for ten years, although the verdict remains subject to appeal.

BoletimSecRansomware & Extortion

Android Ransomware Mantax Otax Encrypts Files and Streams Victim Screen in Real Time

Researchers at Zimperium have identified a new Android ransomware strain called Mantax Otax that combines file encryption with live screen recording and surveillance capabilities. The malware is distributed through sideloaded APK files delivered via messaging apps and phishing messages rather than official app stores. Once installed, it uses AES encryption to lock files with the .enc extension and conducts ransom negotiations directly on the infected device through an on-screen chat interface. In addition to encryption, Mantax Otax continuously captures the screen, saves footage as MP4 video, and streams it to operators while also photographing the surroundings with the device camera. The malware abuses accessibility services to read on-screen content, intercepts SMS messages to steal two-factor authentication codes, and exfiltrates contacts, call logs, browser history, and credentials from WhatsApp and Telegram. It also displays a fake lock screen to capture the device PIN. Impact is reduced on Android 10 and later due to Scoped Storage restrictions, though surveillance functions remain active. Evidence points to a targeted campaign against users in Indonesia.

AntiMalwareRansomware & Extortion

IT Elements 2026 Conference: Ransomware Accounts for 69% of Incidents as Businesses Struggle with Backup Protection and AI Workloads

The fourth IT Elements conference opened in Moscow on September 9, focusing on business continuity after cyberattacks, infrastructure failures, and ransomware incidents. Jet CSIRT data showed that ransomware was responsible for 69% of confirmed incidents in the first half of 2026, with the majority occurring in the second quarter. Experts discussed the challenges of protecting backup copies from compromise, the frequent gap between stated RTO targets and real-world recovery times, and decision-making processes during major outages. The event also covered corporate AI agents, stressing the need for strong Data Governance, Data Quality, and DataOps practices to avoid unreliable model outputs. Research from Jet Infosystems and AC IKS revealed that over 30% of companies have already allocated dedicated network segments for AI workloads, with power demands reaching 80-200 kW per rack. On the networking track, testing of Eltex and EcoRouter devices showed adequate performance in standard scenarios but highlighted the lack of a universal domestic solution. The conference concluded with discussions on workforce changes, noting that AI is altering career paths for junior specialists and increasing demand for professionals who understand business context and can critically evaluate model results.

BoletimSecRansomware & Extortion

Ransomware Operators Linked to The Gentlemen Deploy TukTuk C2 Framework for Espionage and Credential Theft

Operators associated with the ransomware group The Gentlemen have adopted a new command-and-control framework called TukTuk to steal credentials, monitor compromised systems, and prepare environments for ransomware deployment. The framework was discovered on a server that also hosted tools for disabling EDR solutions, research on vulnerable drivers, and data apparently stolen from two large organizations. TukTuk includes agents for both Windows and Linux, along with its own backend and management panel that allows remote command execution, file transfers, screen capture, and device tracking through a single interface. One notable feature displays a fake Windows Security window on the victim's machine to capture entered credentials and send them directly to the attackers' panel. Researchers identified a DLL sideloading technique that abuses the legitimate Greenshot.exe executable to load a malicious log4net.dll library and launch the TukTuk agent. The server also contained EDRKiller, WarsawKiller, and UnknownKiller tools, plus materials on BYOVD attacks that leverage vulnerable legitimate drivers to gain kernel access and interfere with security products.