Also known as: DEV-0832, Vice Society, VICE SPIDER
Vice Society is a ransomware group that has been active since at least June 2021. They primarily target the education and healthcare sectors, but have also been observed targeting the manufacturing industry. The group has used multiple ransomware families and has been known to utilize PowerShell scripts for their attacks. There are similarities between Vice Society and the Rhysida ransomware group, suggesting a potential connection or rebranding.
Executive Summary
Vanilla Tempest, also known as Vice Society (DEV-0832, VICE SPIDER), is a ransomware group active since June 2021. They primarily target the education, healthcare, and manufacturing sectors globally, using multiple ransomware families and PowerShell scripts. The group exhibits similarities to Rhysida, suggesting potential connections or rebranding.
Goals & Targeting
Vanilla Tempest's strategic objectives likely revolve around financial gain through ransom demands. They target sectors where critical services are provided, possibly to maximize disruption impact and influence negotiations. Their victims typically include educational institutions, healthcare providers, and manufacturing companies, which may have high recovery costs or sensitive data.
Enhanced Description
Vanilla Tempest is a prominent ransomware group known for its targeted attacks on critical infrastructures, including education, healthcare, and manufacturing industries. Since their emergence in June 2021, they have demonstrated a sophisticated approach by employing multiple ransomware strains and leveraging PowerShell scripting for execution. Their operations suggest a focus on sectors with high data sensitivity and potentially weaker security frameworks, such as healthcare and education, which may offer higher rewards or easier access points.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Vanilla Tempest operates with a focus on specific sectors, leveraging their tools to encrypt data and demand ransoms. The group may have links to Rhysida, indicating potential operational continuity or rebranding strategies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to limited details on Tactics, Techniques, and Procedures beyond tool usage. Further data is needed on their full capabilities.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics