type: incident ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["incident", "ransomware", "vantacore", "pro-ukraine", "threat-actor"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Defence", "Critical Infrastructure", "Government"] ยท au_impact: false
New Pro-Ukraine 'VantaCore' Gang Targets Russian Companies With Custom Ransomware
Summary
Russian cybersecurity firm F6 documented VantaCore, a ransomware group it assesses as a rebrand of the pro-Ukrainian operation Thor, targeting at least seven Russian organisations since its August detection (leak site dating to early June). Operating as a ransomware-as-a-service outfit with a Tor-based comms channel, VantaCore builds its own toolset โ a proprietary ransomware encrypting servers and endpoints, a VantaCoreLoader propagator, a VantaCoreRAT backdoor and a SnowKiller tool to disable security software โ with ransom demands reaching millions of dollars. F6 says the shift away from LockBit 3 Black and Babuk reflects usable weaknesses in those tools and pro-Ukrainian reluctance to rely on Russian-rooted software.