Unknown · assessed origin Ukraine
VantaCore
Thor
misp-galaxyrefreshed 2026-09-15
sigil
Last 30 days
last seen 14 d ago
1
dispatch
0
victims
0
CVEs seen
Analyst brief
VantaCore is a ransomware group believed to be a rebrand of Thor, targeting Russian organizations with custom-built malware and multimillion-dollar ransom demands. F6 says the group has attacked at least seven victims, uses a ransomware-as-a-service model, and reflects a broader shift among pro-Ukrainian hackers toward in-house tooling instead of LockBit 3 Black and Babuk.
Early access
Track VantaCore on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.
bot-protected