Also known as: vanir group
VanirGroup emerged in mid‑2024 as an outfit composed largely of ex‑members of well‑known ransomware collectives such as LockBit, Karakurt, and Knight. The group’s composition suggests a blend of mature operational experience and existing social engineering channels, allowing it to quickly establish a foothold through affiliate contracts and initial access broker purchases. Tactically, VanirGroup deploys a bespoke ransomware strain that encrypts target data in a fashion similar to its predecessor groups but with unique command‑and‑control mechanisms. Post‑encryption, the malware exfiltrates compromised files to custom leak sites designed with a retro terminal aesthetic; these sites are hosted on minimal back‑end infrastructure and are often revealed by Nginx 404 responses. Ransom negotiations proceed via secure chat portals that allow the operators to communicate directly with victims. The organization operates under an affiliate model founded on trust and reputation within the underground. Affiliates receive revenue in exchange for delivering compromises, and the group has also leveraged Initial Access Broker services for a rapid breakout into target networks. While only three victims have been publicly identified (Beowulfchain, Qinao and Athlon), German law enforcement recently seized part of VanirGroup’s leak infrastructure, indicating active defensive pressure. The group continues to evolve its tactics and maintain a strong online presence across multiple platforms to facilitate coordination and distribution.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
VanirGroup is a mid‑sophistication ransomware operator that surfaced in early July 2024, consisting of former affiliates from LockBit, Karakurt and Knight. They employ an affiliate model, purchase Initial Access Broker services, and deliver custom ransomware that encrypts data, exfiltrates it to bespoke leak sites, and negotiates ransom via chat portals. The group has targeted a broad slice of technology‑related sectors across Germany and Iran, with early victims reported in the IT, defense, and education industries.
Goals & Targeting
VanirGroup’s primary goal is financial gain through ransomware attacks that combine data encryption with external extortion. By targeting high‑value sectors—information technology, defense, education, finance, manufacturing, healthcare and energy—they aim to maximize ransom payouts while diversifying risk across industries. The group’s strategy of using affiliates and IAB services allows rapid penetration into diverse organizations in Germany (DE) and Iran (IR), expanding their threat footprint under the guise of a broad supply‑chain attack model.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
VanirGroup demonstrates a campaign pattern that begins with broker‑purchased initial access, followed by malware delivery through an affiliate or compromised infrastructure. The group rapidly escalates to data encryption, exfiltration to leak sites, and ransom negotiations via chat portals, typically completing the cycle within days. Victims have been predominantly mid‑ to large‑size organizations across IT, defense, education and other sectors in Germany and Iran; no extensive geographical spread has yet been observed beyond these regions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Information about VanirGroup is at a nascent stage, with only three publicly reported victims and limited operational data. Confidence in the core characteristics—ransomware delivery, use of affiliates, and custom leak sites—is moderate due to corroborated sources. However, details on long‑term campaign scope, precise financial metrics, and full extent of tool usage remain incomplete; further intelligence will refine these assessments.
No campaigns linked yet.
No observed data linked yet.
2
Techniques
24
Tools
0
Campaigns
6
IOCs
0
Observed Data
2
Tactics