Ragnarök: F6 Investigates VantaCore Ransomware Attacks and Suspected Thor Rebrand
Specialists from F6’s Laboratory of Digital Forensics and Malware Research have reported a new threat to Russian businesses. In August 2026 the laboratory detected activity from a ransomware group calling itself VantaCore. The confirmed number of victims stands at no fewer than seven, with ransom demands reaching millions of dollars.
Researchers believe VantaCore is a rebrand of the previously known pro-Ukrainian group Thor. F6 has previously documented consolidation and regrouping among pro-Ukrainian collectives during 2025–2026. A parallel trend is the abandonment of LockBit 3 Black and Babuk in favor of custom encryptors. In March 2026 F6 reported that Bearlyfy had switched to its own GenieLocker ransomware; in August the same pattern appeared with VantaCore.
Reasons for dropping LockBit 3 Black and Babuk include their Russian origins and accumulated technical shortcomings. Nevertheless, the new encryptors retain code and design similarities with both families. VantaCore also launched a data-leak site in June 2026 and positioned itself as a professional Ransomware-as-a-Service operation, complete with a Tor chat for victim negotiations.
The group employs double and triple extortion. After encryption, stolen data is sold or published on its leak site and later reused for further attacks against Russian entities. Initial access vectors include poorly secured RDP and VPN services, vulnerabilities in public-facing applications, and compromised partner credentials.
Once inside the network, operators move laterally using harvested legitimate accounts over SMB and RDP. They perform reconnaissance with both custom scanners and native utilities such as ping, netsh, quser, qwinsta and net user. Persistence is achieved through newly created Windows services, while remote access is provided by the legitimate Tactical RMM tool and the custom VantaCoreRAT backdoor written in Go.
To remain undetected, the attackers obfuscate binaries, delete tools and logs after use, clear Windows event logs with PowerShell and wevtutil, and disable security products manually or via the SnowKiller BYOVD utility. Backups are destroyed by overwriting RAID arrays with arbitrary data using the open-source Bootice utility.
Encryption is performed by the custom VantaCore ransomware developed in C++. The binary accepts a hardcoded password on the command line and uses ChaCha20 with X25519 for file encryption. Mass deployment is handled by the custom VantaCoreLoader tool, which spreads via administrative shares in a manner similar to LockBit 3 Black’s psexec_netspread module.
Related articles
WannaCry Ransomware: How EternalBlue Turned One Infection Into a Global Epidemic
On 12 May 2017, the WannaCry ransomware worm rapidly infected more than 230,000 computers across at least 150 countries by exploiting the unpatched SMBv1 vulnerability with the EternalBlue exploit. The malware combined remote code execution via EternalBlue with file encryption and ransom demands in Bitcoin, affecting hospitals, manufacturers, and government organizations worldwide. Microsoft had released the MS17-010 patch two months earlier, yet many systems remained vulnerable due to delayed deployment in large environments. WannaCry scanned both local subnets and random public IPv4 addresses in parallel threads, allowing infected machines to autonomously discover and compromise new targets without user interaction. Security researcher Marcus Hutchins halted the initial wave by registering a hardcoded kill-switch domain, though later variants removed this check. The incident demonstrated how a known, patchable flaw combined with worm-like propagation could produce worldwide operational disruption.
International Law Enforcement Operation Dismantles KillSec Ransomware Group and Seizes 110 TB of Stolen Data
An international operation coordinated by Eurojust with support from Europol has dismantled the infrastructure of the KillSec ransomware group. Authorities seized five servers containing at least 110 terabytes of data stolen from victims and took control of the group's leak site domains. Three individuals were arrested, including a 16-year-old identified as the group's primary administrator and operator. The coordinated action involved law enforcement from nine countries and included eight searches across Spain, Greece, the United Kingdom, and Romania. KillSec has been active since 2024 and is linked to nearly one thousand ransomware incidents worldwide, primarily using a double-extortion model that combines data encryption with threats to publish stolen information. The seized data volume highlights the scale of the group's operations, which frequently targeted healthcare environments where system downtime directly impacts patient care.
ShinyHunters Claims Breach of FBI Recruitment Portal and Demands Eight-Figure Ransom
The hacker group ShinyHunters has publicly claimed responsibility for compromising the FBI's official recruitment website, FBIjobs.gov, asserting access to sensitive data belonging to nearly all FBI agents as well as job applicants. According to the group, the intrusion extended to multiple internal systems including criminal justice databases, human resources platforms, and Medlink. The attackers stated they exploited a zero-day vulnerability in Oracle PeopleSoft to achieve remote code execution and subsequently defaced the careers site with a fabricated seizure notice. The FBI has acknowledged awareness of unauthorized activity on the portal but has not confirmed any data theft or the scope of the intrusion. ShinyHunters is now demanding an eight-figure ransom payment, framing the amount as a minor fraction of its own resources and warning that time is limited. The operation appears to be retaliation for an FBI public statement issued in May regarding the group's prior activities. Independent verification of the claims remains unavailable, and experts note that extortion groups routinely exaggerate the value of stolen data to increase pressure on victims.
PAYLOAD Ransomware Seizes Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
Researchers at Kaspersky have documented an attack by the PAYLOAD ransomware that paralyzes an entire Windows domain without encrypting a single file. Instead of encryption, the operators leverage native Windows policy mechanisms to enforce disruption across the environment. The core of the attack is a malicious Group Policy Object named PAYLOAD linked directly to the root of the Active Directory domain. This placement allows the policy to reach virtually every connected device, turning it into a corporate-wide disruption tool. Through the GPO, the group distributes ransom notes from SYSVOL, replaces wallpapers and lock screens with extortion images displaying the message Welcome to Payload, and disables local administrator accounts on affected machines. A second policy object named win Firewall Off disables the Windows firewall across the entire fleet, increasing exposure during the operation. Initial access occurred in April 2026 via a compromised legitimate domain account on a FortiGate SSL VPN, with possible entry vectors including phishing, password spraying, and credential stuffing. The victim is a manufacturing company in the Middle East. The extortion model combines data theft with operational shutdown, delivering effects similar to traditional ransomware but without any decryption key to negotiate.