Vice Society ransomware appends the .v-society extension when encrypting Linux machines. Running a leak site on the darkweb, Possible relations with "HelloKitty" Known victims: 188 1 ransom note(s) on file
Objectives
Executive Summary
The Vice Society threat actor is a medium-sophistication criminal group primarily motivated by financial gain through ransomware activities targeting Linux-based systems. Known since May 2021, they append files with the .v-society extension upon encryption and operate a dark web leak site, potentially linked to HelloKitty ransomware.
Goals & Targeting
The strategic objectives of Vice Society are centered around financial gain through ransomware campaigns. Their targeting strategy focuses on sectors and individuals where encryption can be applied effectively, with a likely preference for industries that rely heavily on Linux-based infrastructure. The group's victims may include educational institutions, research organizations, or businesses running critical Linux servers, though specific sectoral targeting is not explicitly detailed in the available information. The actor's motivation aligns with typical ransomware operations where financial extraction from victims is the primary aim.
Enhanced Description
The Vice Society threat actor is a cybercriminal group known for deploying ransomware that specifically targets Linux machines. Their operations involve encrypting victim files and appending the '.v-society' file extension to indicate encryption. The group operates a dark web leak site where they presumably公布 details of their victims or demands for ransom payments. There are possible relations between Vice Society and HelloKitty, another known ransomware group, which could imply shared tactics or infrastructure. The actor's operational timeline began in May 2021, and recent activity was recorded up until mid-June 2023, indicating sustained criminal operations. While their primary victims have not been explicitly detailed beyond a count of 188 known cases, the fact that they focus on Linux systems suggests targeting organizations dependent on or running such environments.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Vice Society has demonstrated a sustained operational presence from 2021 to 2023, indicating a structured criminal approach. Their campaigns likely involve initial access via phishing or exploiting vulnerabilities specific to Linux systems, followed by encryption and data theft. The presence of a dark web leak site suggests an organized attempt to pressure victims into paying ransoms by threatening data exposure. Notable operations include multiple ransomware deployments with known victim count reaching 188 individuals or entities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available information about Vice Society is limited to their ransomware activity and possible relations with HelloKitty. While their operational timeline and targets are partially understood, specifics on their exact methods or tools used beyond the known file extension are not detailed. The confidence level in this assessment is moderate as gaps exist in understanding their specific tactics and tools.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics