Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors vanhelsing

Description

VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and splitting ransoms 80/20, supporting Windows, Linux, BSD, ARM, and ESXi targets, reaching at least five victims across the US, France, Italy, and Australia within its first two months. Known victims: 8 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Vanhelsing emerges as a medium sophistication cybercriminal group leveraging ransomware attacks for financial gain. This threat actor operates a multi-platform Ransomware-as-a-Service (RaaS) model, targeting various industries across multiple countries since early 2025. With an affiliate program and rapid expansion, Vanhelsing poses a significant risk to organizations worldwide.

Goals & Targeting

Vanhelsing's strategic objectives center on financial gain through ransomware distribution. Their targeting profile is broad, focusing on industries across multiple countries without specific sector preference. This indicates a tactical approach to exploit any vulnerable organization, leveraging global reach for maximum impact. Victims include various sectors in the US, France, Italy, and Australia, suggesting an initial phase of testing and expansion.

Enhanced Description

Vanhelsing is a recently emerged cybercriminal group operating a Ransomware-as-a-Service (RaaS) model launched on March 7, 2025. The operation requires a $5,000 affiliate deposit and offers an 80/20 revenue split with its partners. This multi-platform ransomware supports Windows, Linux, BSD, ARM, and ESXi targets, demonstrating technical versatility. Within the first two months, Vanhelsing successfully compromised eight organizations across the United States, France, Italy, and Australia. The group's activities indicate a focus on financial gain through organizational disruption, aligning with their primary motivation of 'organizational-gain'. Vanhelsing's multi-platform capability suggests they target a broad range of industries, though specific sectors remain undefined. Their operational timeline, from March 12 to April 5, 2025, highlights rapid execution and geographic reach.

Key Capabilities

  • Multi-platform ransomware development
  • Affiliate program exploitation model
  • Rapid deployment capabilities
  • Geographic targeting across multiple regions

Software / Tooling

Vanhelsing Ransomware
Multi-vector attack tools
Affiliate distribution mechanisms

Campaigns & Victims

Vanhelsing's campaigns show a focus on rapid deployment and broad targeting. Their first campaign affected eight victims in four countries, indicating a quick scaling strategy. The use of multiple platforms suggests operational flexibility and an aim to maximize impact across diverse industries. Future campaign patterns may involve increased affiliate activity and geographic expansion.

IOC Patterns

  • Hash-MD5 patterns associated with their ransomware
  • IP-v4 addresses linked to their infrastructure

Recommended Actions

  • Implement robust network monitoring for multi-platform threats
  • Enhance endpoint protection with specialized ransomware detection tools
  • Conduct regular data backups and ensure offsite storage security
  • Increase user awareness training on phishing attempts
  • Monitor网络 traffic for known Vanhelsing IP addresses

Suggested Tags

ransomware
crime
multiplatform

Confidence Assessment

Confidence in Vanhelsing's data is moderate, with clear evidence of their operational timeline, targets, and IOCs. However, detailed TTPs and toolset specifics remain unclear, creating gaps in understanding their long-term strategies and capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

9

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
crime
multiplatform

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Mar 12, 2025
Last Seen
Apr 5, 2025
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.