A ransomware group believed to be linked to pro-Ukrainian hackers is targeting Russian organizations with custom malware and demanding multimillion-dollar payments, according to new research. The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week. Researchers first detected its activity in August, although the group's data-leak website appears to have been created in early June. Researchers said they believe VantaCore is a rebrand of Thor, a pro-Ukrainian hacking group that was among the more active ransomware operations targeting Russia last year. F6 attributed at least 12 attacks to Thor in 2025. Its operations have combined financial extortion with destructive or politically motivated activity, according to the company. VantaCore, however, appears primarily focused on making money, according to F6, with ransom demands reaching millions of dollars. The group operates as a ransomware-as-a-service operation, a business model in which ransomware developers provide malware and infrastructure to affiliates who carry out attacks. VantaCore communicates with victims through a Tor-based chat service and maintains a leak site where stolen information can be published. The hackers use several common methods to break into corporate networks, including exploiting poorly secured VPNs and other remote-access tools, flaws in internet-facing applications and login credentials stolen from business partners. “Their tactics, techniques and procedures are largely effective, although they are neither sophisticated nor innovative,” F6 said. What sets VantaCore apart from many ransomware operations is its reliance on a collection of custom-built hacking tools. F6 said it detected attacks in August involving the group's proprietary ransomware, also called VantaCore, which can encrypt data on both servers and employees' computers. The attackers use another custom tool, VantaCoreLoader, to distribute the ransomware and other malicious software throughout compromised networks. They also deploy VantaCoreRAT, a backdoor that can gather information about infected systems, transfer files and remotely execute commands. Another tool, dubbed SnowKiller, is designed to disable security software, including antivirus products. Like other pro-Ukrainian hacking groups, VantaCore may use stolen data for more than just extortion, F6 said. Information taken from Russian organizations can be published or sold online and potentially used in further cyberattacks or other operations targeting Russian companies and individuals. The emergence of VantaCore comes amid a broader reorganization of pro-Ukrainian hacking groups that F6 said it observed during 2025 and 2026. Researchers have seen some of these groups stop using widely available ransomware such as LockBit 3 Black and Babuk and instead build their own malware. F6 said the shift is partly driven by weaknesses found in those ransomware tools over time, as well as reluctance among pro-Ukrainian hackers to rely on software with Russian roots.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.