VantaCore

MISP
Type:
Unknown
Country:
UA
First seen:
Unknown
Details:

VantaCore is a ransomware group believed to be a rebrand of Thor, targeting Russian organizations with custom-built malware and multimillion-dollar ransom demands. F6 says the group has attacked at least seven victims, uses a ransomware-as-a-service model, and reflects a broader shift among pro-Ukrainian hackers toward in-house tooling instead of LockBit 3 Black and Babuk.

Aliases (17)
Thor Thor Thor Thor Thor Thor Thor Thor Thor Thor Thor Thor Thor Thor Thor Thor Thor
Metadata
ID: 1122
Created: 04/09/2026 04:00
Updated: 12/09/2026 04:00