Overview

Platforms: Windows · Linux · BSD · ARM · VMware ESXi
Variants: vanhelsing · vanlocker
Extensions: .vanhelsing · .vanlocker
ATT&CK software: VanHelsing ransomware locker
Initial access: Not publicly confirmed
Top countries: US · FR · IT · AU · CL
Observed sectors: Government · Manufacturing · Pharmaceuticals · Healthcare services · Technologies
Tracked victims: 8

Victims

caschile.cl CLAIMED
April 5, 2025 CL Technology 2 tracker sources
Chilean IT company developing software for public and municipal management.
attorneykohm.com CLAIMED
March 31, 2025 US Legal Services 3 tracker sources
Dallas–Fort Worth law firm providing legal representation for more than 25 years.
alertenterprise.com CLAIMED
March 31, 2025 US Technology 3 tracker sources
Technology company focused on physical access control, identity management and workspace automation.
compumedics.com.au AND neuromedicalsupplies.com CLAIMED
March 26, 2025 AU Healthcare 3 tracker sources
Medical technology company developing diagnostic systems for sleep, brain and blood-flow monitoring.
studiocdlvallone.it CLAIMED
March 24, 2025 IT Architecture / Engineering 3 tracker sources
Italian architecture and engineering studio focused on collaborative design.
Show more victims (3)
www.medsrx.com CLAIMED
March 19, 2025 US Healthcare 3 tracker sources
Pharmacy service focused on simplifying medication access and pharmacist support.
Atos-racks.com CLAIMED
March 18, 2025 FR Manufacturing 3 tracker sources
French manufacturer of racks, enclosures and precision sheet-metal products for electronics.
www.cityofbellville.com CLAIMED
March 12, 2025 US Government 3 tracker sources
Municipal government website for Bellville, Texas, the county seat of Austin County.

Operational Activity

Recent Observations

Launch of VanHelsing Ransomware-as-a-Service
March 7, 2025
VanHelsingRaaS launched on March 7, 2025. The operation employs a model requiring a $5,000 deposit from new affiliates, while experienced actors may join without a deposit. Affiliates retain 80% of ransom payments, with operators receiving 20%. The program strictly prohibits attacks against Commonwealth of Independent States (CIS) countries.
Initial Access and Propagation Techniques
March 2025
Affiliates utilize various attack vectors including AI-generated phishing emails (T1566.001), exploitation of vulnerabilities in cloud and remote collaboration tools (T1210), and compromised RDP/VPN credentials via session hijacking (T1078.002). Supply chain compromises (T1195) have also been documented. Lateral movement is facilitated by SMB shares and PsExec.
Double Extortion and Ransomware Deployment
March 2025
The operation employs a double-extortion model, involving data exfiltration prior to file encryption. The ransomware targets Windows, Linux, BSD, ARM, and ESXi systems. Encrypted files are typically appended with '.vanhelsing' (or sometimes '.vanlocker') and 'README.txt' ransom notes are dropped. The malware performs anti-forensic actions, including deleting volume shadow copies.

TTPs

ATT&CK coverage: 8 techniques
T1047 Windows Management Instrumentation
VERIFIED
The ransomware utilizes the WMI framework to execute commands, perform system modifications, and delete volume shadow copies.
T1053.005 Scheduled Task/Job: Scheduled Task
PROBABLE
The ransomware establishes persistence by creating or modifying scheduled tasks on the victim system.
T1059 Command and Scripting Interpreter
VERIFIED
The ransomware uses command-line interpreters to execute malicious operations and manage encryption behavior.
Show more TTPs (5)
T1543.003 Create or Modify System Process: Windows Service
PROBABLE
The malware creates or modifies Windows services to maintain persistence on compromised systems.
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
VERIFIED
The ransomware utilizes registry run keys to achieve persistence and ensure silent execution upon system startup.
T1574.002 Hijack Execution Flow: DLL Side-Loading
PROBABLE
The ransomware employs DLL side-loading to hijack execution flow and evade detection.
T1486 Data Encrypted for Impact
PROBABLE
The ransomware encrypts files using Curve25519 and ChaCha20/Salsa20 algorithms, appending a .vanhelsing extension.
T1490 Inhibit System Recovery
VERIFIED
The malware deletes shadow copies to prevent file restoration, often using wmic commands.

CVEs

Microsoft Office and Windows HTML Remote Code Execution vulnerability exploited in campaigns associated with the VanHelsing ransomware group.
Associated since: August 2024

Infrastructure

Leak site
Tor-based data leak site used by the VanHelsing ransomware operation to publish stolen data from non-paying victims. Multiple onion addresses have been documented in association with this infrastructure.
HISTORICAL
Negotiation portal
Tor-based negotiation portal used by VanHelsing ransomware affiliates to communicate with victims and manage ransom demands.

Attribution

No supported attribution to a specific operator, developer, or related threat actor is currently available.

Affiliates

th30c0der
An individual actor who claimed to possess and attempted to sell the VanHelsing ransomware source code, including the affiliate panel and encryptor builder, for $10,000. VanHelsing operators labeled this individual a former developer attempting a scam, subsequently leading the group to leak their own source code publicly.
First seen: May 2025

Timeline

2025-05-14
Operational Milestone: Five Victims
As of this date, the operation has successfully infected five victims across the United States, France, Italy, and Australia, with data leaked from three of them.
2025-03-16
First Observed Activity
The VanHelsing ransomware strain is first identified and observed in the wild, targeting Windows systems with .vanhelsing file extensions.
2025-03-07
VanHelsing RaaS Program Launch
The VanHelsing Ransomware-as-a-Service (RaaS) operation is launched, requiring a $5,000 entry deposit for new affiliates and offering an 80/20 revenue split. The operation strictly prohibits targeting Commonwealth of Independent States (CIS) nations.

Sources