New pro-Ukraine hacker group targets Russian companies with custom ransomware
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
A ransomware group believed to be linked to pro-Ukrainian hackers is targeting Russian organizations with custom malware and demanding multimillion-dollar payments, according to new research.
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week. Researchers first detected its activity in August, although the group's data-leak website appears to have been created in early June.
Researchers said they believe VantaCore is a rebrand of Thor, a pro-Ukrainian hacking group that was among the more active ransomware operations targeting Russia last year. F6 attributed at least 12 attacks to Thor in 2025. Its operations have combined financial extortion with destructive or politically motivated activity, according to the company.
Source: https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia
Related breach coverage
- Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence2026-09-13
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]
- Ukrainian hacker gets four years in US prison over Conti ransomware attacks2026-09-11
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.
- Cl0p Targets 40+ Organizations Through PTC Windchill Flaw2026-08-21
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has targeted more than 40 organizations through a […]
- Russian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers2026-08-21
The statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company's network traffic analysis platform.