VanHelsing, new RaaS in Town
ID: 2f92e115-755f-5788-bcbe-f2c33a3ce492
STIX ID: report--2f92e115-755f-5788-bcbe-f2c33a3ce492
Feed Name: Check Point Research
VanHelsingRaaS is a newly launched (Mar 2025) and rapidly expanding ransomware-as-a-service operation offering affiliate access (free for reputable affiliates or $5,000 deposit for newcomers) with an 80/20 revenue split; it targets Windows and advertises support for Linux, BSD, ARM, and ESXi. Check Point Research obtained samples and observed active infections (three known victims) with ransom demands up to $500,000; the ransomware is C++-based, uses Curve25519 and ChaCha20 for per-file encryption, supports many command-line options (including SMB spreading and a silent two-stage mode), deletes shadow copies, and ships multiple operational artifacts (PDB path, embedded images, psexec, onion negotiation pages, and a Bitcoin wallet). Indicators of compromise and recommended protections are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
