Skip to content

VectraRAT

VectraRAT is a Windows-focused, rental-only malware-as-a-service remote-access trojan operated by a developer known as Vectra, reportedly formerly Nyxel.

Profile source: Mallory opens in a new tab

VectraRAT

Family profile

VectraRAT is a Windows-focused, rental-only malware-as-a-service remote-access trojan operated by a developer known as Vectra, reportedly formerly Nyxel. The platform comprises a Windows implant, a Linux-based control server, an operator panel, and a payload builder. It provides covert remote control through a hidden virtual desktop, screen capture, remote Command Prompt and PowerShell execution, file transfer, process discovery, keylogging, and SOCKS5 proxying through compromised hosts. Its automated collection component gathers browser credentials, network and system information, and configuration files that can contain sensitive application secrets. VectraRAT can also manipulate clipboard contents to hijack cryptocurrency payment addresses and supports privilege escalation without a user prompt through abuse of trusted Windows auto-elevation functionality. The implant uses a custom TCP command-and-control protocol and can be redirected to new control infrastructure after deployment. Observed distribution included Amadey-mediated deployment and ClickFix social-engineering pages, including tax-themed lures that induced victims to execute attacker-supplied commands. Activity has affected corporate Windows environments, including Enterprise and Windows Server systems, and has included theft of files from business systems.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 15, 2026
Last activity
Sep 15, 2026
Feed role
C2
Host form
3 IP / 0 hostnames

Leading locations

  • HU2
  • NL1

Leading providers

  • ServerAstra Kft.2
  • Omegatech LTD1

Infrastructure traits

  • Hosting 3

Reported operators

Threat actors

2 named in public reporting
Nyxel

VectraRAT is a rental-only Malware-as-a-Service platform that gives a paying operator full remote control of a Windows host, along with automated credential and file collection on first connection.

Vectra

VectraRAT is a rental-only Malware-as-a-Service platform that gives a paying operator full remote control of a Windows host, along with automated credential and file collection on first connection.

MITRE ATT&CK

VectraRAT in ATT&CK

32 distinct techniques

Reporting

Research mentioning VectraRAT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.