Last seven days
- First activity
- Sep 15, 2026
- Last activity
- Sep 15, 2026
- Feed role
- C2
- Host form
- 3 IP / 0 hostnames
VectraRAT is a Windows-focused, rental-only malware-as-a-service remote-access trojan operated by a developer known as Vectra, reportedly formerly Nyxel.
Profile source: Mallory opens in a new tabVectraRAT
VectraRAT is a Windows-focused, rental-only malware-as-a-service remote-access trojan operated by a developer known as Vectra, reportedly formerly Nyxel. The platform comprises a Windows implant, a Linux-based control server, an operator panel, and a payload builder. It provides covert remote control through a hidden virtual desktop, screen capture, remote Command Prompt and PowerShell execution, file transfer, process discovery, keylogging, and SOCKS5 proxying through compromised hosts. Its automated collection component gathers browser credentials, network and system information, and configuration files that can contain sensitive application secrets. VectraRAT can also manipulate clipboard contents to hijack cryptocurrency payment addresses and supports privilege escalation without a user prompt through abuse of trusted Windows auto-elevation functionality. The implant uses a custom TCP command-and-control protocol and can be redirected to new control infrastructure after deployment. Observed distribution included Amadey-mediated deployment and ClickFix social-engineering pages, including tax-themed lures that induced victims to execute attacker-supplied commands. Activity has affected corporate Windows environments, including Enterprise and Windows Server systems, and has included theft of files from business systems.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
VectraRAT is a rental-only Malware-as-a-Service platform that gives a paying operator full remote control of a Windows host, along with automated credential and file collection on first connection.
VectraRAT is a rental-only Malware-as-a-Service platform that gives a paying operator full remote control of a Windows host, along with automated credential and file collection on first connection.
MITRE ATT&CK
Reporting
Researchers uncovered VectraRAT, a previously undocumented Windows remote-access trojan sold exclusively as a malware-as-a-service subscription for $250 per month. Operated by a developer using the aliases Vectra and formerly Nyxel, the full-stack platform enables surveillance, credential theft, remote command execution, file transfer, proxying, and privilege escalation on compromised systems. SOCRadar discovered the operation through an exposed directory containing malware samples, server-side components, licenses, and operator logs, then identified more than 10 related servers. Operators delivered VectraRAT through Amadey loader campaigns and ClickFix pages impersonating TurboTax that prompt victims to paste commands into the Windows Run dialog; logs showed 38 genuine sessions in less than a week, with corporate Windows editions—including Enterprise and Windows Server 2025—accounting for 48% of records containing operating-system data.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.