Skip to content
skopnix
← adversaries
Unknown · assessed origin Ukraine

VantaCore

Thor
misp-galaxyrefreshed 2026-09-15

sigil

Last 30 days

last seen 14 d ago

1
dispatch
0
victims
0
CVEs seen
Analyst brief

VantaCore is a ransomware group believed to be a rebrand of Thor, targeting Russian organizations with custom-built malware and multimillion-dollar ransom demands. F6 says the group has attacked at least seven victims, uses a ransomware-as-a-service model, and reflects a broader shift among pro-Ukrainian hackers toward in-house tooling instead of LockBit 3 Black and Babuk.

On the wire
Take it with you
References
Early access

Track VantaCore on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected