Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Vanilla Tempest

Also known as: DEV-0832, Vice Society, VICE SPIDER

Description

Vice Society is a ransomware group that has been active since at least June 2021. They primarily target the education and healthcare sectors, but have also been observed targeting the manufacturing industry. The group has used multiple ransomware families and has been known to utilize PowerShell scripts for their attacks. There are similarities between Vice Society and the Rhysida ransomware group, suggesting a potential connection or rebranding.

AI Analysis

· 1 week ago

Executive Summary

Vanilla Tempest, also known as Vice Society (DEV-0832, VICE SPIDER), is a ransomware group active since June 2021. They primarily target the education, healthcare, and manufacturing sectors globally, using multiple ransomware families and PowerShell scripts. The group exhibits similarities to Rhysida, suggesting potential connections or rebranding.

Goals & Targeting

Vanilla Tempest's strategic objectives likely revolve around financial gain through ransom demands. They target sectors where critical services are provided, possibly to maximize disruption impact and influence negotiations. Their victims typically include educational institutions, healthcare providers, and manufacturing companies, which may have high recovery costs or sensitive data.

Enhanced Description

Vanilla Tempest is a prominent ransomware group known for its targeted attacks on critical infrastructures, including education, healthcare, and manufacturing industries. Since their emergence in June 2021, they have demonstrated a sophisticated approach by employing multiple ransomware strains and leveraging PowerShell scripting for execution. Their operations suggest a focus on sectors with high data sensitivity and potentially weaker security frameworks, such as healthcare and education, which may offer higher rewards or easier access points.

Key Capabilities

  • Ransomware deployment
  • PowerShell-based attacks

MITRE ATT&CK Tactics

Execution
Defense Evasion

ATT&CK Techniques

T1059.002

Software / Tooling

PowerShell scripts

Campaigns & Victims

Vanilla Tempest operates with a focus on specific sectors, leveraging their tools to encrypt data and demand ransoms. The group may have links to Rhysida, indicating potential operational continuity or rebranding strategies.

IOC Patterns

  • Use of PowerShell scripting
  • Encrypted files indicative of ransomware activity

Recommended Actions

  • Enhance email filtering to detect phishing attempts
  • Monitor PowerShell activity for unusual scripts

Suggested Tags

Ransomware
Education
Healthcare

Confidence Assessment

Low confidence due to limited details on Tactics, Techniques, and Procedures beyond tool usage. Further data is needed on their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Education
Healthcare

Details

Type
Unknown
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.