Md5
7 total3e063dc0de937df5841cb9c2ff3e46515c254d25751269892b6f02d6c6384aef5b28a0fc21ba079b380effb30e853132d7ad18e63064ef80cc6b98db54516f6f97150d47ea7779101be6582fc329c2cd084deb26cd9d8eff3f972e8e0c4adfe66dc5021a0cbdbe6dea26d78afb43ebb3
VanHelsing is a ransomware-as-a-service operation that emerged in March 2025 and provides a multi-platform file-encrypting malware family for affiliate use.
Profile source: Mallory opens in a new tabVanHelsing
VanHelsing is a ransomware-as-a-service operation that emerged in March 2025 and provides a multi-platform file-encrypting malware family for affiliate use. It is primarily documented as targeting Windows, with additional advertised support for Linux, BSD, ARM-based environments, and VMware ESXi. The operation follows the common double-extortion model by encrypting victim data while also operating a leak site used to pressure victims with the threat of publishing stolen information. Public reporting indicates the group explicitly prohibits attacks against Russian and other CIS-linked organizations, a pattern consistent with parts of the Russian-speaking cybercrime ecosystem.
On Windows, VanHelsing encrypts files and has been observed appending variants such as .vanhelsing and .vanlocker to affected data. It drops a ransom note named README.txt, changes the victim desktop wallpaper, and directs victims to Tor-based negotiation infrastructure. The malware excludes selected system-critical files, extensions, and directories from encryption to preserve system operability, and it creates a mutex associated with its family name. Reported command-line options indicate configurable execution behavior, including reduced logging and options suggestive of operation across local and remote resources. The family has also been associated with shadow copy deletion and process hollowing or similar process-injection tradecraft intended to inhibit recovery and reduce detection.
VanHelsing has been linked to attacks affecting organizations in multiple countries, including the United States, Italy, France, and Australia, with manufacturing among the most represented victim sectors in early observed leak-site postings. At least one municipal government victim has also been reported, indicating broad opportunistic targeting rather than a narrow industry focus. Reporting on initial access remains limited, though lateral movement via administrative tooling has been associated with the operation in some analyses.
The operation gained additional attention after source code related to its affiliate panel, leak blog, and Windows builder was publicly released following an internal dispute involving a former developer. The leak raised concern about copycat campaigns and downstream reuse, as has occurred previously with other leaked ransomware builders. VanHelsing operators subsequently indicated plans to continue development under a newer version.
3e063dc0de937df5841cb9c2ff3e46515c254d25751269892b6f02d6c6384aef5b28a0fc21ba079b380effb30e853132d7ad18e63064ef80cc6b98db54516f6f97150d47ea7779101be6582fc329c2cd084deb26cd9d8eff3f972e8e0c4adfe66dc5021a0cbdbe6dea26d78afb43ebb3FEE914521FB507AB978107ACE3B69B4CA41DA89859408BAE23E1512E8C2E614A26C5FFD482A3193.37.69.225193.37.69.162bc1qw92kdpnedjd037lxej9q9336y05v7gql0u4qcvbc1q0cuvj9eglxk43v9mqmyjzzh6m8qsvsanedwrruMITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.