New Pro-Ukraine Group 'VantaCore' Targets Russian Firms with Custom Ransomware
A new pro-Ukraine hacking collective, VantaCore, is actively targeting Russian companies with custom ransomware, demanding millions in ransom and marking a significant evolution in the cyber conflict.

A newly emerged ransomware operation, believed to be aligned with pro-Ukrainian interests, is systematically targeting Russian organizations with bespoke malware and demanding substantial ransoms, according to recent cybersecurity research. The group, operating under the name VantaCore, has already impacted at least seven known victims, as detailed in a report by Russian cybersecurity firm F6. While researchers first observed VantaCore's activity in August, the group's data-leak website was reportedly established in early June, suggesting a period of preparation before public operations.
Security analysts suspect VantaCore is a rebranding of the Thor group, a pro-Ukrainian hacking collective that was notably active in targeting Russia throughout 2025, with F6 attributing at least 12 attacks to Thor last year. While Thor's operations often blended financial extortion with politically motivated or destructive activities, VantaCore appears to be primarily driven by financial gain, with ransom demands escalating into the millions of dollars. This focus on monetary profit aligns with the common ransomware-as-a-service (RaaS) model, where developers provide malware and infrastructure to affiliates who then conduct the attacks.
VantaCore employs a typical RaaS operational structure, communicating with victims via a Tor-based chat service and maintaining a dedicated leak site for publishing exfiltrated data. Their initial network intrusions leverage common, albeit often poorly secured, methods. These include exploiting vulnerable VPNs and other remote access solutions, targeting flaws in internet-facing applications, and utilizing stolen login credentials obtained from business partners. F6 noted that while these tactics are effective, they are neither particularly sophisticated nor innovative.
What distinguishes VantaCore from many other ransomware operations is its significant reliance on a suite of custom-developed hacking tools. The group deploys its proprietary ransomware, also named VantaCore, capable of encrypting data across both server infrastructure and individual employee workstations. To facilitate network-wide compromise, they utilize VantaCoreLoader, a custom tool designed for distributing the ransomware and other malicious payloads. Furthermore, VantaCoreRAT, a custom backdoor, enables the attackers to gather intelligence on infected systems, transfer files, and execute commands remotely.
Adding to their arsenal is SnowKiller, a custom tool specifically engineered to disable or evade security software, including antivirus products. This multi-faceted toolkit allows VantaCore to establish a persistent presence, encrypt data, and evade detection within compromised networks. The development and deployment of these custom tools suggest a dedicated and resourced operation, moving beyond reliance on off-the-shelf malware.
Similar to other pro-Ukrainian hacking collectives, VantaCore may leverage stolen data beyond mere financial extortion. Information pilfered from Russian entities could be published or sold on illicit forums, potentially fueling further cyberattacks or other operations targeting Russian companies and individuals. This dual-use of exfiltrated data underscores the complex motivations and multifaceted nature of cyber warfare.
The emergence of VantaCore coincides with a broader trend of reorganization observed among pro-Ukrainian hacking groups throughout 2025 and 2026, according to F6. Researchers have noted a shift away from widely available ransomware strains like LockBit 3 Black and Babuk, towards the development of indigenous malware. This strategic pivot is attributed to several factors, including the discovery of weaknesses in commonly used ransomware tools over time and a reluctance among pro-Ukrainian actors to utilize software with potential Russian origins or ties.
The group's activities highlight the evolving landscape of cyber conflict in the context of the ongoing war in Ukraine. As established tools become scrutinized or deprecated, new, custom-built operations like VantaCore emerge, demonstrating adaptability and a continued commitment to disrupting Russian entities through cyber means, primarily driven by financial incentives.