Overview
Platforms:
Windows · Linux · BSD · ARM · VMware ESXi
Variants:
vanhelsing · vanlocker
Extensions:
.vanhelsing · .vanlocker
ATT&CK software:
VanHelsing ransomware locker
Initial access:
Not publicly confirmed
Top countries:
US · FR · IT · AU · CL
Observed sectors:
Government · Manufacturing · Pharmaceuticals · Healthcare services · Technologies
Tracked victims:
8
Victims
caschile.cl
CLAIMED
Chilean IT company developing software for public and municipal management.
attorneykohm.com
CLAIMED
Dallas–Fort Worth law firm providing legal representation for more than 25 years.
alertenterprise.com
CLAIMED
Technology company focused on physical access control, identity management and workspace automation.
compumedics.com.au AND neuromedicalsupplies.com
CLAIMED
Medical technology company developing diagnostic systems for sleep, brain and blood-flow monitoring.
studiocdlvallone.it
CLAIMED
Italian architecture and engineering studio focused on collaborative design.
Show more victims (3)
www.medsrx.com
CLAIMED
Pharmacy service focused on simplifying medication access and pharmacist support.
Atos-racks.com
CLAIMED
French manufacturer of racks, enclosures and precision sheet-metal products for electronics.
www.cityofbellville.com
CLAIMED
Municipal government website for Bellville, Texas, the county seat of Austin County.
Operational Activity
Recent Observations
Launch of VanHelsing Ransomware-as-a-Service
March 7, 2025
VanHelsingRaaS launched on March 7, 2025. The operation employs a model requiring a $5,000 deposit from new affiliates, while experienced actors may join without a deposit. Affiliates retain 80% of ransom payments, with operators receiving 20%. The program strictly prohibits attacks against Commonwealth of Independent States (CIS) countries.
Initial Access and Propagation Techniques
March 2025
Affiliates utilize various attack vectors including AI-generated phishing emails (T1566.001), exploitation of vulnerabilities in cloud and remote collaboration tools (T1210), and compromised RDP/VPN credentials via session hijacking (T1078.002). Supply chain compromises (T1195) have also been documented. Lateral movement is facilitated by SMB shares and PsExec.
Double Extortion and Ransomware Deployment
March 2025
The operation employs a double-extortion model, involving data exfiltration prior to file encryption. The ransomware targets Windows, Linux, BSD, ARM, and ESXi systems. Encrypted files are typically appended with '.vanhelsing' (or sometimes '.vanlocker') and 'README.txt' ransom notes are dropped. The malware performs anti-forensic actions, including deleting volume shadow copies.
TTPs
ATT&CK coverage:
8 techniques
T1047
Windows Management Instrumentation
VERIFIEDThe ransomware utilizes the WMI framework to execute commands, perform system modifications, and delete volume shadow copies.
T1053.005
Scheduled Task/Job: Scheduled Task
PROBABLEThe ransomware establishes persistence by creating or modifying scheduled tasks on the victim system.
T1059
Command and Scripting Interpreter
VERIFIEDThe ransomware uses command-line interpreters to execute malicious operations and manage encryption behavior.
Show more TTPs (5)
T1543.003
Create or Modify System Process: Windows Service
PROBABLEThe malware creates or modifies Windows services to maintain persistence on compromised systems.
T1547.001
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
VERIFIEDThe ransomware utilizes registry run keys to achieve persistence and ensure silent execution upon system startup.
T1574.002
Hijack Execution Flow: DLL Side-Loading
PROBABLEThe ransomware employs DLL side-loading to hijack execution flow and evade detection.
T1486
Data Encrypted for Impact
PROBABLEThe ransomware encrypts files using Curve25519 and ChaCha20/Salsa20 algorithms, appending a .vanhelsing extension.
T1490
Inhibit System Recovery
VERIFIEDThe malware deletes shadow copies to prevent file restoration, often using wmic commands.
CVEs
Microsoft Office and Windows HTML Remote Code Execution vulnerability exploited in campaigns associated with the VanHelsing ransomware group.
Associated since:
August 2024
Infrastructure
Leak site
Tor-based data leak site used by the VanHelsing ransomware operation to publish stolen data from non-paying victims. Multiple onion addresses have been documented in association with this infrastructure.
HISTORICAL
Negotiation portal
Tor-based negotiation portal used by VanHelsing ransomware affiliates to communicate with victims and manage ransom demands.
Attribution
No supported attribution to a specific operator, developer, or related threat actor is currently available.
Affiliates
th30c0der
An individual actor who claimed to possess and attempted to sell the VanHelsing ransomware source code, including the affiliate panel and encryptor builder, for $10,000. VanHelsing operators labeled this individual a former developer attempting a scam, subsequently leading the group to leak their own source code publicly.
First seen:
May 2025
Timeline
2025-05-14
Operational Milestone: Five Victims
As of this date, the operation has successfully infected five victims across the United States, France, Italy, and Australia, with data leaked from three of them.
2025-03-16
First Observed Activity
The VanHelsing ransomware strain is first identified and observed in the wild, targeting Windows systems with .vanhelsing file extensions.
2025-03-07
VanHelsing RaaS Program Launch
The VanHelsing Ransomware-as-a-Service (RaaS) operation is launched, requiring a $5,000 entry deposit for new affiliates and offering an 80/20 revenue split. The operation strictly prohibits targeting Commonwealth of Independent States (CIS) nations.
Sources
New VanHelsing Ransomware Operation
Check Point
Show more sources (20)
VanHelsing Ransomware
CYFIRMA
Analysis of VanHelsing Ransomware Operations
IndustrialCyber
VanHelsing ransomware builder leaked on hacking forum
BleepingComputer
Vanhelsing Ransomware
SK shieldus EQST
VanHelsing Ransomware
Broadcom Inc.
VanHelsing Ransomware | WatchGuard Technologies
WatchGuard Technologies