logo

VanHelsing: Inside the Rise of a Multi‑Platform RaaS Threat Actor

ID: ecf89e27-dd87-5599-b92a-84e1b78fa981

STIX ID: report--ecf89e27-dd87-5599-b92a-84e1b78fa981

Feed Name: Brandefense Blog

Threat Score
78/100

Date Published: 2026-01-15

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

VanHelsing is a commercially oriented Ransomware-as-a-Service that supports Windows (x86 and ARM), Linux, and VMware ESXi, enabling affiliates to conduct enterprise-targeted attacks; a leaked ransomware builder in late 2024 accelerated distribution and led to forks and increased use by lower-skilled actors. The report details affiliate-driven initial access methods (credential abuse, RDP/VPN/SSH exploitation, access brokers), lateral movement techniques, multi-threaded and VM-aware encryption, double-extortion practices, observed engineering improvements, and recommended mitigations for virtualization and credential hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.