A newly identified ransomware operation calling itself VantaCore is targeting Russian organizations with custom-built malware, multimillion-dollar ransom demands, and infrastructure presented as part of a ransomware-as-a-service operation.
Russian cybersecurity company F6 said it has identified at least seven known victims associated with VantaCore activity. Researchers first detected the group’s operations in August 2026, though its data-leak site appears to have been established in early June.
F6 assesses that VantaCore is likely a rebrand of the pro-Ukrainian ransomware group THOR, which was active against Russian organizations during 2025. F6 previously attributed at least 12 attacks to THOR in 2025, placing it among the more active pro-Ukrainian ransomware groups targeting Russian entities during that period.
The attribution remains an assessment by F6 rather than an independently established fact. The researchers linked VantaCore to THOR based on operational similarities and the broader evolution of pro-Ukrainian ransomware activity.
F6 identified THOR as one of the more active pro-Ukrainian ransomware groups targeting Russian organizations in 2025. VantaCore’s current activity appears primarily financially motivated, with F6 stating that its goal is first and foremost to profit from victims and that ransom demands reach millions of dollars.
That shift is significant because it places VantaCore closer to a conventional ransomware business model even though its suspected origins remain tied to a politically aligned threat ecosystem.
The group communicates with victims through a Tor-based chat service and operates a data-leak site where stolen information can be published if victims refuse to meet ransom demands.
According to F6, VantaCore affiliates have relied on familiar enterprise intrusion methods rather than highly novel exploitation techniques. Initial access can involve poorly protected VPN infrastructure, other remote-access services, vulnerabilities in internet-facing applications, and credentials stolen from third parties or business partners.
F6 characterized the group’s tactics, techniques, and procedures as effective without being especially sophisticated or innovative.
The more distinctive part of the operation is VantaCore’s growing collection of internally developed malware.
Researchers observed attacks in August involving the group’s proprietary ransomware, also named VantaCore, which is capable of encrypting data on both servers and employee workstations.
The group also uses VantaCoreLoader, a custom loader designed to distribute the ransomware and other malicious components throughout compromised environments.
Another tool, VantaCoreRAT, functions as a remote-access backdoor. According to F6’s findings, it can collect information about infected systems, transfer files, and execute commands remotely, giving attackers continuing control after a network has been compromised.
Alongside its internally developed tools, VantaCore uses SnowKiller, an AV/EDR-killing utility designed to neutralize security products through a bring-your-own-vulnerable-driver, or BYOVD, technique.
F6 describes VantaCore as presenting itself as a ransomware-as-a-service, or RaaS, operation, supported by a dedicated leak site and Tor-based victim communication infrastructure.
The combination of a loader, remote-access Trojan, defensive-evasion component, and ransomware payload suggests the group is attempting to reduce dependence on publicly available offensive tools and create a more self-contained attack framework.
That development fits a broader trend F6 has documented among pro-Ukrainian hacking groups operating against Russian organizations.
During 2025, F6 identified Bearlyfy/LABUBU, THOR, 3119/TR4CK, Blackjack/Mordor, and Shadow among the more active pro-Ukrainian groups targeting Russian organizations. THOR alone was linked by F6 to at least 12 attacks during the year.
F6 also reported that 15 percent of ransomware incidents it tracked in 2025 were primarily destructive rather than financially motivated, compared with 10 percent in 2024. That distinction is important in the Russian threat environment because some ransomware campaigns have used encryption and data destruction as operational weapons rather than solely as leverage for payment.
Other pro-Ukrainian ransomware groups have also been moving toward proprietary malware.
F6 reported in March that Bearlyfy, also known as LABUBU, began replacing tools such as LockBit 3 Black, Babuk variants, and other reused ransomware with custom-developed encryptors. One of those tools, GenieLocker, was introduced in attacks beginning in March 2026.
That shift can provide attackers with several advantages. Custom malware can reduce reliance on leaked or widely analyzed ransomware families, complicate defensive detection rules, and allow operators to tailor encryption, persistence, and evasion functions to their own requirements.
Political alignment can add another consideration. F6 has noted reluctance among some pro-Ukrainian actors to continue relying on ransomware families with Russian origins, creating an incentive to develop independent malware.
VantaCore’s suspected evolution from THOR would fit that pattern: an established group retains its targeting and operational knowledge while changing its identity, infrastructure, and tooling.
The group’s use of stolen information may also extend beyond ordinary double extortion.
F6 said data stolen from Russian organizations can later be published or sold and then reused in additional attacks or other destructive activity. Compromised credentials, internal documentation, infrastructure details, and employee information can provide material for follow-on intrusion attempts against either the original victim or connected organizations.
That creates a secondary risk for suppliers, contractors, technology partners, and other businesses connected to a compromised company.
F6’s broader 2025–2026 threat reporting shows that ransomware attacks against Russian organizations continued to rise in 2025, with the number of recorded ransomware incidents increasing 15 percent compared with 2024. The company also documented substantial growth in ransom demands, with the highest initial demand observed during 2025 reaching hundreds of millions of rubles.
The emergence of VantaCore therefore reflects two overlapping developments: the continued financial expansion of ransomware operations and the restructuring of politically aligned hacking groups into more independent, technically self-sufficient organizations.
At least seven VantaCore victims are currently known to F6, but that number should not be treated as the complete size of the campaign. Ransomware incidents are not always publicly disclosed, and some victims may never appear on leak sites if negotiations, containment, or other factors prevent publication.
The available research also does not establish that every VantaCore attack is politically motivated. F6’s current assessment points to a group with suspected pro-Ukrainian lineage whose present operations appear primarily focused on financial extortion.
That distinction remains important as VantaCore develops. A group originating from a politically motivated ecosystem can still operate primarily as a criminal ransomware enterprise, and individual campaigns may combine financial, intelligence, disruptive, and ideological objectives.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



