INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
VectraRAT Malware Exploits Windows for Remote Access
| 2026-09-15 16:45 MEDIUM HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
The emergence of VectraRAT, a previously undocumented platform that includes a full-featured Windows implant, command-and-control (C2) infrastructure, and an operator panel built entirely from scratch rather than based on existing malware. This sophisticated malware is capable of delivering attackers a hidden desktop, remote CMD and PowerShell access, keylogging, file transfer, process discovery, clipboard manipulation, and SOCKS5 proxy functionality. The malware can also exfiltrate files from compromised systems, making it a highly effective tool for cyber operations. Its use of Amadey loader and ClickFix pages as delivery vectors adds an extra layer of complexity to its attack surface. VectraRAT's ability to operate on high-value hosts such as corporate Windows editions has significant implications for organizations, highlighting the need for robust defense measures against this type of threat.
Technical Mitigations AI-generated
* Implement a robust and up-to-date antivirus solution to detect and prevent malware infections.
* Regularly update operating systems, software, and applications to ensure they have the latest security patches and features.
* Use strong passwords and multi-factor authentication (MFA) for all accounts, including those used for remote access or network management.
* Conduct regular security audits and penetration testing to identify vulnerabilities and weaknesses in enterprise networks.
* Educate employees on phishing attacks, social engineering tactics, and best practices for secure communication and data transfer.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ve•••••.google
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
AmadeyAmadey
Target & Sectors
DACH
DACH
NORTH_AMERICA
NORTH_AMERICA
financefinance
governmentgovernment
Incident Timeline
August 2022
VectraRAT is delivered through the Amadey loader and ClickFix pages, which are popular social engineering vectors for attackers.
Click on any entity below to view its context and source!
organisation
UAC
"It's very sophisticated, does user account control (UAC) bypass, it uses proprietary protocols for C2, and is priced like any midtier software-as-a-service (SaaS) application."
A Snapshot of the VectraRAT Malware
The operator behind VectraRAT has been active for nearly four years without detection; the researchers found an older identity, "Nyxel," with a YouTube channel dating back to August 2022.
tactic
T1588.001 - Malware
"It's very sophisticated, does user account control (UAC) bypass, it uses proprietary protocols for C2, and is priced like any midtier software-as-a-service (SaaS) application."
A Snapshot of the VectraRAT Malware
The operator behind VectraRAT has been active for nearly four years without detection; the researchers found an older identity, "Nyxel," with a YouTube channel dating back to August 2022.
organisation
YouTube
"It's very sophisticated, does user account control (UAC) bypass, it uses proprietary protocols for C2, and is priced like any midtier software-as-a-service (SaaS) application."
A Snapshot of the VectraRAT Malware
The operator behind VectraRAT has been active for nearly four years without detection; the researchers found an older identity, "Nyxel," with a YouTube channel dating back to August 2022.
organisation
Run
From a human observer perspective, the researchers also gave defense notes for defending against
ClickFix
as an initial entry vector, noting that "a verification page that asks someone to open the Run dialog and paste a command is never legitimate," and advising that they used a single rule to close the delivery path used "in the most active campaign we documented," according to the report.
organisation
ClickFix
The malware is delivered through Amadey loader and
ClickFix
pages, the latter of which is a popular social engineering vector for attackers.
organisation
Outbound TCP 3308
These include specific IoCs that come in the form of a C2 override file; Outbound TCP 3308: auto-elevation abuse; a debug API sequence; and a hidden PowerShell, among others included in the report.
organisation
API
These include specific IoCs that come in the form of a C2 override file; Outbound TCP 3308: auto-elevation abuse; a debug API sequence; and a hidden PowerShell, among others included in the report.
data_breach
3308 Outbound TCP
These include specific IoCs that come in the form of a C2 override file; Outbound TCP 3308: auto-elevation abuse; a debug API sequence; and a hidden PowerShell, among others included in the report.
infrastructure
Windows
Moreover, operators selected high-value hosts for hands-on exfiltration afterward, with 48% of victim entries corresponding to corporate Windows editions, including
Windows Enterprise
, Enterprise LTSC, IoT Enterprise LTSC, and Windows Server 2025.
organisation
Windows Enterprise
Moreover, operators selected high-value hosts for hands-on exfiltration afterward, with 48% of victim entries corresponding to corporate Windows editions, including
Windows Enterprise
, Enterprise LTSC, IoT Enterprise LTSC, and Windows Server 2025.
organisation
IoT Enterprise LTSC
Moreover, operators selected high-value hosts for hands-on exfiltration afterward, with 48% of victim entries corresponding to corporate Windows editions, including
Windows Enterprise
, Enterprise LTSC, IoT Enterprise LTSC, and Windows Server 2025.
organisation
ClickFix Campaign Compromises
Related:
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
User Account Control Bypass Sets the RAT Apart
VectraRAT also incorporates a
UAC-bypass
technique that can obtain a high-integrity process without showing the victim the usual elevation prompt.
organisation
Nyxel Hub
However, the rebrand appears to be merely "marketing deep" — the researchers observed the operator presenting "the old Nyxel Hub and the new VectraHub side by side, with no functional difference between them," according to the report.
organisation
VectraHub
However, the rebrand appears to be merely "marketing deep" — the researchers observed the operator presenting "the old Nyxel Hub and the new VectraHub side by side, with no functional difference between them," according to the report.
organisation
AV
The developer also demonstrated scan results against named antivirus (AV) products, "while noting that detection varies by product, version, and configuration," according to the researchers.
organisation
Calderone
"It's pretty obvious that this is being sold as a solution for attacking higher-value corporate targets," Calderone says.
organisation
VectraRAT Means
What VectraRAT Means for Cyber Defenders
For defenders, the appearance of VectraRAT goes beyond just giving them another RAT to detect with security measures.
financial
$50 $ tier
"This is the part of VectraRAT that separates it from the $50 tier," according to the report.
as early as October 2025
VectraRAT was used to target enterprises as early as October 2025.
March 2026
VectraRAT was used to target enterprises in March 2026.
April 2026
Threat actors exploited a vulnerability in WebDAV to gain unauthorized access to the Ukrainian government's network.
Click on any entity below to view its context and source!
industry
Government
Related:
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Ukrainian Government Impacted
The discovery of a second attack on a Ukrainian government entity began in April 2026 with an investigation into a DLL called verification.google executing from WebDAV at that organization, according to the report.
target_region
Ukraine
Related:
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Ukrainian Government Impacted
The discovery of a second attack on a Ukrainian government entity began in April 2026 with an investigation into a DLL called verification.google executing from WebDAV at that organization, according to the report.
observable
verification.google
Related:
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Ukrainian Government Impacted
The discovery of a second attack on a Ukrainian government entity began in April 2026 with an investigation into a DLL called verification.google executing from WebDAV at that organization, according to the report.
attribution
DLL
Related:
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Ukrainian Government Impacted
The discovery of a second attack on a Ukrainian government entity began in April 2026 with an investigation into a DLL called verification.google executing from WebDAV at that organization, according to the report.
general_metric
15 Bugs Expose Risks
Related:
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Ukrainian Government Impacted
The discovery of a second attack on a Ukrainian government entity began in April 2026 with an investigation into a DLL called verification.google executing from WebDAV at that organization, according to the report.
June 23
Threat actors used Telegram to communicate with the VectraRAT malware developer.
Click on any entity below to view its context and source!
organisation
Telegram
SOCRadar didn't discover the platform until June 23, when its researchers observed an open directory that led them to investigate across more than 10 servers, dozens of samples, panel logs belonging to real operators, and a Telegram conversation with the platform's developer.
infrastructure
10 servers
SOCRadar didn't discover the platform until June 23, when its researchers observed an open directory that led them to investigate across more than 10 servers, dozens of samples, panel logs belonging to real operators, and a Telegram conversation with the platform's developer.
2026/09/08
Threat actors used spear phishing to target enterprises with VectraRAT, a malware that can hack Windows systems for $250 per month.
2026/09/15
Threat actors used lures to get targets to paste a code snippet directly into the Chrome Web browser's navigation bar, and then further manipulated them by displaying fake Google CAPTCHA that uses ClickFix technique.
Click on any entity below to view its context and source!
organisation
Cloudflare Workers
"Both of these campaigns abuse services defenders already trust, Google Sheets, Cloudflare Workers, public blockchain endpoints, for command and control," observes Denis Calderone, principal and chief technology officer at Suzu Labs.
organisation
Suzu Labs
"Both of these campaigns abuse services defenders already trust, Google Sheets, Cloudflare Workers, public blockchain endpoints, for command and control," observes Denis Calderone, principal and chief technology officer at Suzu Labs.
organisation
Run
Specifically, Svajcer says they should "educate users that no legitimate CAPTCHA, verification workflow, vulnerability report or support process should require them to paste code into the address bar, an extension, the Run dialog, PowerShell, or a terminal."
organisation
CAPTCHA
Specifically, Svajcer says they should "educate users that no legitimate CAPTCHA, verification workflow, vulnerability report or support process should require them to paste code into the address bar, an extension, the Run dialog, PowerShell, or a terminal."
organisation
ClickFix
The link between the two was not only in their use of social engineering attacks, commonly known as ClickFix and
ClearFake
, but also in how they abused legitimate services and assets to make the malicious activity resemble typical user or application behavior, according to the researchers.
infrastructure
Windows
VectraRAT Can Hack Windows Enterprises for $250 per Month.
Researchers from SOCRadar discovered VectraRAT, a previously undocumented platform that includes a full-featured Windows implant, command-and-control (C2) infrastructure, and an operator panel built entirely from scratch rather than based on existing malware, according to a new
report
published.
Related:
SpiderSilk Hunts External Threats With AI-Based Scanner
VectraRAT
is a different case, however, in which "every layer of it, the Linux control server, the Windows implant, the protocol between them, the licensing that keeps operators paying, was written by the same developer," according to the report.
Upon further scrutiny, the researchers traced an attack that started with a compromised website displaying a fake Google
CAPTCHA
that uses the ClickFix technique to trick victims into pasting a command into the Windows Run dialog.
organisation
VectraRAT Can Hack Windows Enterprises
VectraRAT Can Hack Windows Enterprises for $250 per Month.
organisation
VectraRAT
Researchers from SOCRadar discovered VectraRAT, a previously undocumented platform that includes a full-featured Windows implant, command-and-control (C2) infrastructure, and an operator panel built entirely from scratch rather than based on existing malware, according to a new
report
published.
infrastructure
Linux
Related:
SpiderSilk Hunts External Threats With AI-Based Scanner
VectraRAT
is a different case, however, in which "every layer of it, the Linux control server, the Windows implant, the protocol between them, the licensing that keeps operators paying, was written by the same developer," according to the report.
organisation
SpiderSilk Hunts External
Related:
SpiderSilk Hunts External Threats With AI-Based Scanner
VectraRAT
is a different case, however, in which "every layer of it, the Linux control server, the Windows implant, the protocol between them, the licensing that keeps operators paying, was written by the same developer," according to the report.
organisation
ClickFix Campaign Compromises
Related:
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
"Both operations turn the victim into an active part of the infection chain and abuse services or technologies that users and defenders normally regard as legitimate," Vanja Svajcer, senior threat researcher at Cisco Talos, tells Dark Reading.
organisation
Cisco Talos
Related:
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
"Both operations turn the victim into an active part of the infection chain and abuse services or technologies that users and defenders normally regard as legitimate," Vanja Svajcer, senior threat researcher at Cisco Talos, tells Dark Reading.
organisation
XWorm
A leaked
AsyncRAT
build, a cracked XWorm license, a
QuasarRAT
fork with a new icon and a new name," according to SOCRadar's report.
organisation
SOCRadar
A leaked
AsyncRAT
build, a cracked XWorm license, a
QuasarRAT
fork with a new icon and a new name," according to SOCRadar's report.
financial
$250 customers
And using it costs customers only $250 per month.
infrastructure
Microsoft 365
Related:
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
Abusing Legitimate Google Services
organisation
NovaCookies
Related:
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
Abusing Legitimate Google Services
organisation
Google
In a deviation from typical ClickFix attacks, the attackers convince potential victims to retrieve and enter malicious browser code from a publicly available Google Sheet, using a legitimate Google service as part of their infrastructure.
organisation
TamperMonkey
"
Threat actors used lures to get targets to paste a code snippet directly into the Chrome Web browser's navigation bar; however, by the latest version, the attackers were focused on a legitimate
Chrome plug-in
, TamperMonkey, "to inject a loader script pasted in by the user and [to] provide persistence across sessions with the current targeted site," he wrote.
organisation
Google Sheets
Then, after frequent disruption of their posts on shared text sites, the actors moved in July to hosting all the components of their campaign in Google Docs and Google Sheets, according to Gallagher.
organisation
DLL
That command retrieves a disguised dynamic link library (DLL) file over WebDAV and launches the
Amatera infostealer
, which can harvest cryptocurrency data, credentials, browser information, and sensitive files.
organisation
NetSupport
One branch of the malware also deployed a cryptocurrency stealer and reverse proxy, while another installed NetSupport Manager to give attackers remote control of the infected system, according to the report.
organisation
Amatera
Though just one organization prompted the investigation, the researchers eventually realized that "the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload," Svajcer wrote in the post.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Moreover, operators selected high-value hosts for hands-on exfiltration afterward, with 48% of victim entries corresponding to corporate Windows editions, including
Windows Enterprise
, Enterprise LTSC, IoT Enterprise LTSC, and Windows Server 2025.
VectraRAT Can Hack Windows Enterprises for $250 per Month.
Researchers from SOCRadar discovered VectraRAT, a previously undocumented platform that includes a full-featured Windows implant, command-and-control (C2) infrastructure, and an operator panel built entirely from scratch rather than based on existing malware, according to a new
report
published.
Related:
SpiderSilk Hunts External Threats With AI-Based Scanner
VectraRAT
is a different case, however, in which "every layer of it, the Linux control server, the Windows implant, the protocol between them, the licensing that keeps operators paying, was written by the same developer," according to the report.
Upon further scrutiny, the researchers traced an attack that started with a compromised website displaying a fake Google
CAPTCHA
that uses the ClickFix technique to trick victims into pasting a command into the Windows Run dialog.
Metrics
infrastructure
Linux
Affected Product
Related:
SpiderSilk Hunts External Threats With AI-Based Scanner
VectraRAT
is a different case, however, in which "every layer of it, the Linux control server, the Windows implant, the protocol between them, the licensing that keeps operators paying, was written by the same developer," according to the report.
Metrics
infrastructure
10
Servers
SOCRadar didn't discover the platform until June 23, when its researchers observed an open directory that led them to investigate across more than 10 servers, dozens of samples, panel logs belonging to real operators, and a Telegram conversation with the platform's developer.
Metrics
data_breach
3,308
Outbound Tcp
These include specific IoCs that come in the form of a C2 override file; Outbound TCP 3308: auto-elevation abuse; a debug API sequence; and a hidden PowerShell, among others included in the report.
Metrics
financial
250
Customers
And using it costs customers only $250 per month.
Metrics
financial
50
$ Tier
"This is the part of VectraRAT that separates it from the $50 tier," according to the report.
Metrics
infrastructure
Microsoft 365
Affected Product
Related:
'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
Abusing Legitimate Google Services
Intelligence Sources
Dark Reading
2026-09-15
Dark Reading
2026-09-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-16T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
Run
entity
7x
timeline
Temporal Reference
2025
date
4x
target region
Target Country
United States
country
4x
tactic
Cyber Operation Type
Social Engineering
tactic
3x
industry
Targeted Sector
Technology
sector
3x
tactic
MITRE ATT&CK Technique
T1059.001 - PowerShell
technique
3x
infrastructure
Affected Product
Windows
software
3x
attribution
Attributing Entity
ClearFake
authority
2x
malware
Malware Payload
Denis
tool
Contextual Telemetry
Context Block
9 METRICS
general metric
%
48
%
general metric
Campaign Compromises
31
campaign compromises
infrastructure
Servers
10
servers
data breach
Outbound Tcp
3,308
outbound tcp
financial
Customers
250
customers
financial
$ Tier
50
$ tier
source region
Origin Country
Russian Federation
country
general metric
Bugs Expose Risks
15
bugs expose risks
general metric
Sessions
365
sessions
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.