Pro‑Ukraine Hackers Deploy Custom Ransomware Against Russian Firms, F6 Reports
A newly identified hacker collective calling itself VantaCore has launched a wave of ransomware attacks against Russian businesses, according to a report released by Russian cybersecurity firm F6 earlier this week.
The report, which names at least seven confirmed victims, says the group is explicitly pro‑Ukraine and has crafted its own ransomware strain to infiltrate target networks. F6’s analysis indicates that the malware is designed to encrypt data and demand payment in cryptocurrency, a pattern common among financially motivated ransomware operators but here tied to a political motive.
Cyber conflict between Moscow and Kyiv has intensified since the start of the war, with both state‑backed and independent actors using digital tools to disrupt each other's infrastructure. Hacktivist groups that align with Ukraine have increasingly turned to ransomware as a way to inflict economic pain while also raising the cost of doing business for entities perceived as supporting the Russian war effort.
While the full scope of the campaign remains unclear, the seven identified victims span a range of sectors, including logistics, manufacturing, and information technology. In each case, the attackers reportedly gained initial access through phishing emails or vulnerable remote‑desktop services before deploying the ransomware payload.
F6 warned that the VantaCore operation demonstrates a higher level of technical sophistication than typical opportunistic ransomware gangs. The firm advised Russian companies to tighten email security, enforce multi‑factor authentication, and regularly back up critical data offline to mitigate the risk of encryption attacks.
Analysts say the emergence of VantaCore reflects a broader trend of politically motivated cyber actors leveraging financially lucrative tools such as ransomware. As the conflict continues, both sides are likely to see more hybrid attacks that blend espionage, sabotage, and extortion, prompting heightened vigilance across the affected regions.
Comments (0)
Be the first to comment.
Join the discussion