Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors vicesociety

Description

Vice Society ransomware appends the .v-society extension when encrypting Linux machines. Running a leak site on the darkweb, Possible relations with "HelloKitty" Known victims: 188 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The Vice Society threat actor is a medium-sophistication criminal group primarily motivated by financial gain through ransomware activities targeting Linux-based systems. Known since May 2021, they append files with the .v-society extension upon encryption and operate a dark web leak site, potentially linked to HelloKitty ransomware.

Goals & Targeting

The strategic objectives of Vice Society are centered around financial gain through ransomware campaigns. Their targeting strategy focuses on sectors and individuals where encryption can be applied effectively, with a likely preference for industries that rely heavily on Linux-based infrastructure. The group's victims may include educational institutions, research organizations, or businesses running critical Linux servers, though specific sectoral targeting is not explicitly detailed in the available information. The actor's motivation aligns with typical ransomware operations where financial extraction from victims is the primary aim.

Enhanced Description

The Vice Society threat actor is a cybercriminal group known for deploying ransomware that specifically targets Linux machines. Their operations involve encrypting victim files and appending the '.v-society' file extension to indicate encryption. The group operates a dark web leak site where they presumably公布 details of their victims or demands for ransom payments. There are possible relations between Vice Society and HelloKitty, another known ransomware group, which could imply shared tactics or infrastructure. The actor's operational timeline began in May 2021, and recent activity was recorded up until mid-June 2023, indicating sustained criminal operations. While their primary victims have not been explicitly detailed beyond a count of 188 known cases, the fact that they focus on Linux systems suggests targeting organizations dependent on or running such environments.

Key Capabilities

  • Linux-targeted ransomware
  • Dark web leak site operation
  • Encryption of victim files using .v-society extension

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Impact

ATT&CK Techniques

T1078
T1566.001
T1566.002

Software / Tooling

Vice Society ransomware
HelloKitty ransomware (possible link)

Campaigns & Victims

The Vice Society has demonstrated a sustained operational presence from 2021 to 2023, indicating a structured criminal approach. Their campaigns likely involve initial access via phishing or exploiting vulnerabilities specific to Linux systems, followed by encryption and data theft. The presence of a dark web leak site suggests an organized attempt to pressure victims into paying ransoms by threatening data exposure. Notable operations include multiple ransomware deployments with known victim count reaching 188 individuals or entities.

IOC Patterns

  • Ransom note appended with .v-society extension
  • File names containing 'Vice Society'
  • Dark web leak site

Recommended Actions

  • Implement robust backup solutions to protect against ransomware encryption
  • Monitor network traffic for signs of encrypted files or unusual activities
  • Educate employees about phishing and social engineering tactics
  • Deploy endpoint detection and response (EDR) tools
  • Enforce multi-factor authentication (MFA) where possible

Suggested Tags

APT
ransomware
financial-gain
Linux

Confidence Assessment

The available information about Vice Society is limited to their ransomware activity and possible relations with HelloKitty. While their operational timeline and targets are partially understood, specifics on their exact methods or tools used beyond the known file extension are not detailed. The confidence level in this assessment is moderate as gaps exist in understanding their specific tactics and tools.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
financial-gain
Linux

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 31, 2021
Last Seen
Jun 20, 2023
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.