Discovery Enum
- Advanced IP Scanner
- Advanced Port Scanner
Vice Society is a financially motivated ransomware operation first identified in 2021.
Profile source: Mallory opens in a new tabVice Society
Vice Society is a financially motivated ransomware operation first identified in 2021. It has conducted double-extortion attacks, exfiltrating victim data before encrypting systems and threatening publication when ransom demands are not met. The operation has particularly targeted education and healthcare organizations, while also affecting manufacturing, government, logistics, and other enterprise environments internationally. Vice Society initially deployed third-party ransomware, including HelloKitty/Five Hands and Zeppelin, before using a custom ransomware variant for Windows and Linux systems.
Observed Vice Society intrusions have involved exploitation of the PrintNightmare vulnerabilities CVE-2021-1675 and CVE-2021-34527, abuse of compromised remote-access credentials, and exploitation of public-facing applications. Operators and associated affiliates have performed network discovery, credential dumping, Active Directory database theft, remote-service lateral movement, data staging and exfiltration, security-tool and process termination, shadow-copy deletion, and event-log clearing. They have also used backdoors and proxy tooling to maintain access. A tracked affiliate cluster transitioned from deploying Vice Society to Rhysida while retaining substantially similar tradecraft; available evidence does not conclusively establish that Vice Society itself rebranded as Rhysida.
Reported operators
Название: Vice Society. Вероятно спин-офф от HelloKitty ... Группа вымогателей Vice Society теперь активно использует уязвимость PrintNightmare (CVE-2021-1675 и CVE-2021-34527).
Secureworks calls that group Gold Victor and it operated a ransomware scheme called Vice Society.
"...we identified a ransomware affiliate group move from deploying Vice Society to leveraging Rhysida ransomware in attacks against enterprises."
Exploited software
MITRE ATT&CK
Reporting
The Rhysida ransomware operation has intensified its focus on healthcare, with reporting and government guidance describing an expanding threat that has hit organizations across Western Europe, the Americas, and Australia. U.S. health-sector alerts and vendor research say the group has targeted education, government, manufacturing, technology, managed service providers, and increasingly healthcare and public health entities. Researchers have also linked Rhysida to tactics associated with the defunct Vice Society operation, while earlier incidents included the leak of stolen documents from the Chilean Army and suspected involvement in disruptive attacks on medical providers. Security reporting says Rhysida commonly gains initial access through phishing and then uses tools such as Cobalt Strike and PowerShell to disable defenses, delete shadow copies, alter RDP settings, and deploy ransomware. In a newly reported healthcare case, SIA Medical Centre was listed as a victim, with the attackers claiming theft of roughly 20,000 patient medical records along with staff identity documents, plaintext credentials, HR files, and legal and financial records. The allegedly exposed data included names, dates of birth, Medicare numbers, clinical notes, insurance files, passports, driver’s licenses, and login credentials, underscoring the group’s dual risk of operational disruption and large-scale sensitive data exposure in the health sector.
HelloKitty ransomware emerged as a targeted extortion threat that gained broad attention after being linked to the attack on game studio CD Projekt Red. Researchers described the malware as less stealthy than major families such as Ryuk, REvil, and Conti, but still highly disruptive, with operators using Tor-based payment portals, customized ransom notes, and in some cases auctioning stolen data on underground forums. The family has also been referred to as Kitty, and reporting tied it to later variants and related offshoots including FiveHands, Kitty Go, Kitty Linux, Vice Society, and Boombye.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.