Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors vendetta

Also known as: tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, coordinat, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, JokerDPR

Description

Vendetta emerged in early 2023 as a rebranded variant of the win.cuba ransomware family. Leveraging both traditional malware delivery methods—such as phishing emails, malicious attachments, and compromised credentials—to establish initial access, the threat actor subsequently builds persistence through cloud‑native techniques. They routinely deploy malicious container images or modified cloud service configurations (e.g., AWS Lambda, Google Apps Script, Cloudflare Workers) that remain dormant until triggered, effectively blending with legitimate operations. Beyond persistence, Vendetta demonstrates a clear appetite for exploitation across the entire attack lifecycle. The actors purchase physical servers and cloud instances to stage watering holes, launch credential‑stealing payloads, and funnel exfiltration traffic through publicly hosted services like GitHub or Twitter. They also routinely employ active reconnaissance scanning of target IP ranges, vulnerability discovery, and brute‑force probing to locate exploitable hosts. From a post‑compromise standpoint, the organization builds an in‑house toolkit comprising malware, exploits, process‑injection utilities, and custom C2 protocols. This toolkit is disseminated via droppers or backdoors bundled with legitimate cloud images. The operational tempo suggests that Vendetta relies on automated collection, exfiltration, and lateral movement tactics to maximize monetary extraction before detection. Overall, vendetta combines cloud‑centric persistence with classic phishing‑based initial access, creating a hybrid adversary model that is difficult to attribute or mitigate without deep visibility into the victim’s cloud and container environments.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Defense
Financial services
Manufacturing
Aerospace
Media
Government
Energy
Education
Critical infrastructure
Information technology
Telecommunications
Healthcare
Nuclear
Chemical
Maritime
Legal services
Transportation

Targeted Countries / Regions

UA
CN
RU
AU
US
IL
IR
TW
TR
FR
KP
KR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Vendetta is a mid‑sophistication criminal organization focused on financial gain through ransomware, BEC, and crypto exploitation. The group uses sophisticated cloud‑based persistence, active reconnaissance, and spearphishing to infiltrate a wide range of sectors including defense, finance, healthcare, and critical infrastructure.

Goals & Targeting

Vendetta seeks rapid financial returns primarily through ransomware extortion, business email compromise (BEC), and cryptocurrency laundering. Their targeting spans virtually every high‑value sector—in particular defense, finance, manufacturing, aerospace, media, and critical infrastructure—across a broad geographic footprint that includes the US, EU, Middle East, Asia, and Russia & its satellite states. By exploiting public cloud platforms for staging and communication while leveraging insider access via spearphishing with legitimate accounts, Vendetta can remain covert for extended periods. The group’s strategy relies on a low‑visibility persistence mechanism: implanting malicious code in container images or modifying cluster RBAC to persist within orchestration frameworks. This approach allows them to ride cloud infrastructure updates, bypass typical perimeter defenses, and stay active as long as the underlying image is used.

Enhanced Description

Key Capabilities

  • Maintain persistent access via container orchestration modifications and cloud image manipulation
  • Use rented physical servers and cloud instances for staging, watering holes, phishing, and C2 activity
  • Register publicly available services (Google, GitHub, Twitter) to conceal C2 traffic and exfiltration
  • Deploy serverless cloud infrastructure as covert C2 channels (Cloudflare Workers, AWS Lambda, Google Apps Script)
  • Distribute malware through online advertising to obfuscate origin
  • Perform active reconnaissance of IP blocks and victim networks via scanning
  • Vulnerability scanning to identify exploitable hosts
  • Iteratively probe infrastructure using brute‑force and crawling techniques for content discovery
  • Compromise email accounts to facilitate spearphishing campaigns (BEC) and maintain trust
  • Build in-house malware, exploits, post‑compromise tools, custom C2 protocols, self‑signed certificates
  • Financial theft via ransomware extortion, BEC, crypto exploitation
  • Leverage malicious AWS/GCP/Azure images and container runtimes for persistence
  • Internal spearphishing using compromised legitimate accounts to elevate trust

MITRE ATT&CK Tactics

Initial Access
Credential Access
Privilege Escalation
Defense Evasion
Persistence
Execution
Collection
Exfiltration
Command and Control
Resource Development
Impact

ATT&CK Techniques

T1037
T1557
T1583
T1123
T1547
T1119
T1115
T1530
T1082
T1071
T1140
T1219
T1036
T1055
T1010
T1560
T1185
T1580
T1217
T1595
T1548
T1087
T1059
T1020
T1083
T1612
T1497
T1098
T1110
T1531
T1027
T1486
T1671
T1197
T1650
T1651
T1134
T1018
T1538
T1105
T1195.002
T1078
T1566.002

Software / Tooling

Vermin
SocGholish
Cuba
netsh
PsExec
PowerShell
Rhadamanthys
Matrix
Dark
Netsupport Manager
Hook
Nexus
Payload
Inter
KongTuke
MintsLoader
Interception
Leverage
systemd
8Base
Global
Handala
RedCap
STOP
Vendetta
Vidar
Process Hollowing
Backdoors
AppDomainManager
Windows Command Shell
LummaC2
WhatsApp
Telegram
GitHub
Remote access tools
BITS
Rundll32
Trojan
UNC1549
MSBuild

Campaigns & Victims

Vendetta’s operations exhibit a cloud‑centric cadence, with multiple deployment vectors including malicious container images installed in legitimate registries and serverless functions used for command and control. Their known campaigns—referred to only loosely as “Win.Cuba rebrandings”—display evidence of active reconnaissance over a short window (mid-February 2023), suggesting rapid deployment cycles. Victim footprints span several high‑profile sectors, typically small or medium enterprises within defense‑related verticals or governmental entities in the United States and European Union. While only three confirmed victims are publicly documented to date, the lack of broader attribution hints at a low‑profile approach that relies heavily on automated exploitation tools and stolen credentials. The group’s methodology is consistent with modern supply‑chain attacks: acquiring pre‑existing malware components (droppers, backdoors) and integrating them into freshly minted cloud or container images. This reduces development overhead and increases operational stealth. Operational pace is moderate but deliberate—leveraging existing infrastructure to reduce detection risk while executing data‑centric exfiltration and ransomware payouts. Future threat intelligence should focus on monitoring cloud image registries for anomalous modifications, as well as tracking phishing campaigns that use compromised legitimate accounts, which appear to be a core launch vector.

IOC Patterns

  • domain
  • file
  • hash-md5
  • malicious cloud or container image implanted in registry
  • use of legitimate internal accounts for spearphishing
  • acquisition of stolen/purchased malware including dropper/backdoor/packer

Recommended Actions

  • Enforce strict signing and verification controls for all cloud/container images
  • Monitor registry changes and enforce least privilege on account access
  • Implement MFA, anomaly detection, and phishing awareness training for employees
  • Deploy C2 traffic monitoring for public services (GitHub, Twitter, Google)
  • Secure serverless function configurations to limit exposure
  • Apply regular vulnerability scanning and prompt patching of exposed hosts
  • Harden container orchestration clusters—restrict RoleBinding/ClusterRoleBinding modifications
  • Lock down infrastructure credentials and restrict privileged roles
  • Deploy EDR capable of detecting process hollowing, obfuscated binaries, and credential theft
  • Monitor for suspicious usage of BITS jobs, PowerShell scripts, Rundll32 execution

Suggested Tags

financial-theft
cloud-persistence
spearphishing-employee
malware-acquisition
ransomware-extortion
BEC
crypto-exploitation
container-persistence
supply-chain-compromise
credential-access
process-injection
defense-evasion
exfiltration
command-and-control

Confidence Assessment

The available evidence for Vendetta is limited to a short activity window in February 2023, with only three documented victims and generic references to the Win.Cuba ransomware. While numerous ATT&CK techniques and tool names are associated, many remain high‑level or inferred from attacker behavior rather than confirmed artifacts. Key gaps include lack of detailed malware samples, definitive attribution of known variants, and comprehensive coverage of long‑term operational patterns. Consequently, confidence in specific tactics and infrastructure claims is moderate but warrants continuous monitoring as additional data emerges.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. cloud.google.com — Cited by web research for: coordinat
  3. www.recordedfuture.com — Cited by web research for: T1497
  4. www.trendmicro.com — Cited by web research for: 8Base
  5. www.group-ib.com — Cited by web research for: LummaC2
  6. redcanary.com — Cited by web research for: SocGholish
  7. attack.mitre.org — Cited by web research for: Process Hollowing

Intel Summary

43

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
APT
ransomware
financial-gain
emerging threat
financial-theft
cloud-persistence
spearphishing-employee
malware-acquisition
ransomware-extortion
BEC
crypto-exploitation
container-persistence
supply-chain-compromise
credential-access
process-injection
defense-evasion
exfiltration
command-and-control

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Feb 12, 2023
Last Seen
Feb 27, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.