Full Report
VanHelsingRaaS, a new ransomware-as-a-service program, infected three victims within two weeks of release, demanding ransoms of $500,000
Analysis Summary
# Threat Actor: VanHelsingRaaS Operators (RaaS Provider)
## Attribution & Identity
This entry focuses on the operators behind the **VanHelsingRaaS** Ransomware-as-a-Service platform. Attribution to specific individuals or nation-states is not provided in the context, but the operational choice to avoid encrypting systems in **Commonwealth of Independent States (CIS) countries** suggests potential alignment or operational practices common among **Russian cybercriminal groups**.
**Known Aliases and Associated Groups:**
* RaaS Platform: VanHelsingRaaS
## Activity Summary
VanHelsingRaaS launched on **March 7, 2025**.
Within the first two weeks of operation, Check Point Research (CPR) observed the service successfully infecting **three victims**, demanding ransoms up to **$500,000**. The model is highly collaborative, offering free access to established affiliates while requiring a **$5,000 deposit** for new affiliates.
## Tactics, Techniques & Procedures
- **Service Model:** Operates as a Ransomware-as-a-Service (RaaS) model, sharing 80% of ransom proceeds with affiliates (20% retained by operators).
- **Platform Support:** Highly versatile, targeting **Windows, Linux, BSD, ARM, and ESXi** systems.
- **Operational Control:** Affiliates manage attacks via an "**intuitive control panel**."
- **Encryption Precision:** The ransomware, written in C++, utilizes **command-line arguments** to allow precise control over the encryption scope (full drives, specific directories, or individual files).
- **Evasion & Persistence:** Includes features designed to **evade detection and ensure persistence**.
- **Geographic Exclusions:** Explicitly programmed **not to encrypt systems in CIS countries**.
## Targeting
- **Sectors:** Not explicitly detailed, but the high ransom demands ($500,000) suggest a focus on organizations capable of high payouts.
- **Geography:** Operations are observed globally, but there is a specific exclusion zone: **CIS countries are intentionally avoided**.
- **Victims:** Three initial victims confirmed within the first two weeks. Specific organizational names are not mentioned.
## Tools & Infrastructure
- **Malware Families Used:**
* **VanHelsing locker:** Described as a "sophisticated encryption tool" written in C++.
- **Infrastructure:**
* **Control Panel:** An "intuitive control panel" used by affiliates for attack management.
* *Note: No specific C2 domains or IPs were provided in the context.*
## Implications
The rapid adoption and infection rate (three victims in two weeks) indicate that VanHelsingRaaS is achieving significant traction quickly, potentially due to attractive revenue sharing (80/20 split) and technical breadth (supporting server, desktop, and virtualization targets like ESXi). Although the encryption process is noted as being in an "early stage of development," its cross-platform capabilities make it a versatile and immediate threat to diverse IT environments.
## Mitigations
- **Monitor for Cross-Platform Threats:** Implement robust detection and response capabilities capable of identifying C++ based malware across Windows, Linux, and virtualization environments (ESXi).
- **Review Affiliate Access Policies:** Organizations should be wary of infiltration techniques commonly used by RaaS affiliates (e.g., exposed RDP, phishing).
- **Patch/Update Encryption Tooling:** Given the ransomware is noted to have "unfinished functionalities," timely patching of potential exploit vectors used initially by affiliates remains critical until the malware evolves.
- **Geographic Restriction Context:** While CIS exclusion is noted, security teams should not assume the exclusion is permanent or universally applied; treat all regions as primary targets.