Skip to content

Vice Society

Vice Society is a financially motivated ransomware operation first identified in 2021.

Profile source: Mallory opens in a new tab

Vice Society

Family profile

Vice Society is a financially motivated ransomware operation first identified in 2021. It has conducted double-extortion attacks, exfiltrating victim data before encrypting systems and threatening publication when ransom demands are not met. The operation has particularly targeted education and healthcare organizations, while also affecting manufacturing, government, logistics, and other enterprise environments internationally. Vice Society initially deployed third-party ransomware, including HelloKitty/Five Hands and Zeppelin, before using a custom ransomware variant for Windows and Linux systems.

Observed Vice Society intrusions have involved exploitation of the PrintNightmare vulnerabilities CVE-2021-1675 and CVE-2021-34527, abuse of compromised remote-access credentials, and exploitation of public-facing applications. Operators and associated affiliates have performed network discovery, credential dumping, Active Directory database theft, remote-service lateral movement, data staging and exfiltration, security-tool and process termination, shadow-copy deletion, and event-log clearing. They have also used backdoors and proxy tooling to maintain access. A tracked affiliate cluster transitioned from deploying Vice Society to Rhysida while retaining substantially similar tradecraft; available evidence does not conclusively establish that Vice Society itself rebranded as Rhysida.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
6
Leak sites
0 available

Discovery Enum

  • Advanced IP Scanner
  • Advanced Port Scanner

Exfiltration

  • MEGA
  • RClone
  • WinSCP

LOLBAS

  • Minidump
  • NTDS Utility (ntdsutil)
  • PsExec
  • WMIC

Networking

  • Proxychains

Offsec

  • Cobalt Strike
  • Impacket
  • PowerShell Empire
  • PowerSploit

RMM Tools

  • PowerAdmin

Reported operators

Threat actors

3 named in public reporting
Vanilla Tempest

Название: Vice Society. Вероятно спин-офф от HelloKitty ... Группа вымогателей Vice Society теперь активно использует уязвимость PrintNightmare (CVE-2021-1675 и CVE-2021-34527).

Gold Victor

Secureworks calls that group Gold Victor and it operated a ransomware scheme called Vice Society.

TAC5279

"...we identified a ransomware affiliate group move from deploying Vice Society to leveraging Rhysida ransomware in attacks against enterprises."

Exploited software

Vulnerabilities linked to Vice Society

2 CVEs

MITRE ATT&CK

Vice Society in ATT&CK

18 distinct techniques

Reporting

Research mentioning Vice Society

Aug 13
Hookphish

Ransomware Group rhysida Hits: SIA Medical Centre

The Rhysida ransomware operation has intensified its focus on healthcare, with reporting and government guidance describing an expanding threat that has hit organizations across Western Europe, the Americas, and Australia. U.S. health-sector alerts and vendor research say the group has targeted education, government, manufacturing, technology, managed service providers, and increasingly healthcare and public health entities. Researchers have also linked Rhysida to tactics associated with the defunct Vice Society operation, while earlier incidents included the leak of stolen documents from the Chilean Army and suspected involvement in disruptive attacks on medical providers. Security reporting says Rhysida commonly gains initial access through phishing and then uses tools such as Cobalt Strike and PowerShell to disable defenses, delete shadow copies, alter RDP settings, and deploy ransomware. In a newly reported healthcare case, SIA Medical Centre was listed as a victim, with the attackers claiming theft of roughly 20,000 patient medical records along with staff identity documents, plaintext credentials, HR files, and legal and financial records. The allegedly exposed data included names, dates of birth, Medicare numbers, clinical notes, insurance files, passports, driver’s licenses, and login credentials, underscoring the group’s dual risk of operational disruption and large-scale sensitive data exposure in the health sector.

Aug 9
Bleeping Computer

Rhysida ransomware behind recent attacks on healthcare

Aug 9
Trend Micro Research

An Overview of the New Rhysida Ransomware | Trend Micro (US)

Aug 8
Talosintelligence Other

What Cisco Talos knows about the Rhysida ransomware

Sep 2
Sentinelone Labs Subdomain

HelloKitty Ransomware Lacks Stealth, But Still Strikes Home - SentinelLabs

HelloKitty ransomware emerged as a targeted extortion threat that gained broad attention after being linked to the attack on game studio CD Projekt Red. Researchers described the malware as less stealthy than major families such as Ryuk, REvil, and Conti, but still highly disruptive, with operators using Tor-based payment portals, customized ransom notes, and in some cases auctioning stolen data on underground forums. The family has also been referred to as Kitty, and reporting tied it to later variants and related offshoots including FiveHands, Kitty Go, Kitty Linux, Vice Society, and Boombye.

Feb 11
Emsisoft

HelloKitty ransomware group likely responsible for CD Projekt attack. Here’s why.

Oct 1
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": HelloKitty, Kitty

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.