VectraRAT Malware-as-a-Service Offers Full Enterprise Compromise for $250/Month
A sophisticated, custom-built malware-as-a-service platform named VectraRAT is providing cybercriminals with a comprehensive toolkit for Windows enterprise network compromise, available for a low monthly subscription.

A newly identified malware-as-a-service (MaaS) platform, dubbed VectraRAT, is enabling threat actors to conduct sophisticated attacks against Windows enterprises for a remarkably low monthly fee of $250. Researchers from SOCRadar have uncovered this fully custom-built platform, which includes a potent Windows implant, dedicated command-and-control (C2) infrastructure, and an operator panel, all developed from scratch by a single, previously undetected developer.
Unlike many MaaS offerings that are often forks or modifications of existing malware, VectraRAT stands out due to its entirely proprietary nature. The platform's architecture, from the Linux control server to the Windows implant and the communication protocol between them, was built from the ground up. This bespoke development approach, coupled with a subscription model designed to ensure ongoing revenue for the operator, distinguishes it in the crimeware market.
The developer behind VectraRAT has been active for approximately four years, initially operating under the alias 'Nyxel' with a presence on YouTube dating back to August 2022. The rebranding to VectraRAT appears to be a marketing effort, as functional differences between the older 'Nyxel Hub' and the new 'VectraHub' were not observed. SOCRadar's investigation began on June 23rd after discovering an open directory that led them to analyze multiple servers, numerous malware samples, operator logs, and even direct communications with the developer.
During their investigation, SOCRadar found that the developer also offered supplementary services, such as custom crypting to evade antivirus detection, for an additional monthly fee ranging from $100 to $350. A bundled package, including crypting and other features, was quoted at over $2,000. The developer demonstrated scan results against various antivirus products, acknowledging that detection rates varied based on product, version, and configuration.
A typical VectraRAT deployment provides a wide array of capabilities commonly found in mature remote access trojans (RATs). Delivered via loaders like Amadey or through social engineering tactics such as ClickFix pages, the malware, once installed, can offer attackers a hidden desktop, remote command-line and PowerShell access, keylogging, file transfer, process discovery, clipboard manipulation, and SOCKS5 proxy functionality. Crucially, it also automatically searches for and exfiltrates sensitive files like .env, .conf, and .config files upon initial connection to the C2 server.
One of VectraRAT's most significant distinguishing features is its User Account Control (UAC) bypass technique. This allows attackers to gain elevated privileges and execute processes with high integrity without triggering the standard UAC prompt that would alert the user. This capability transforms a compromised user workstation into a more powerful platform for subsequent malicious activities, such as credential theft, lateral movement, and deeper network infiltration.
While SOCRadar's analysis did not reveal specific targeting patterns regarding geography or industry, the victim data indicated a prevalence of infections in the US, Russia, and Germany. A significant portion of the identified victims (48%) were running corporate Windows editions, including Enterprise, Enterprise LTSC, IoT Enterprise LTSC, and Windows Server 2025, suggesting a focus on higher-value targets. The confirmed exfiltration of files from these systems underscores the platform's effectiveness in achieving its objectives.
The emergence of VectraRAT highlights a broader trend in the cybercrime economy: the increasing professionalization and subscription-based delivery of sophisticated attack infrastructure. This lowers the technical barrier to entry for less skilled threat actors, while simultaneously presenting a more formidable and evolving challenge for cybersecurity defenders who must contend with custom-built, constantly updated tools.