Vanilla Tempest is a financially motivated cybercriminal threat actor tracked by Microsoft as DEV-0832 and widely associated with the Vice Society and Vice Spider aliases; reporting also links the group to the Rapid Brigantine name. The actor has been active since at least 2021 and is best known for ransomware, data theft, and extortion operations, particularly against education and health care organizations, while also targeting manufacturing, information technology, and other sectors. It has been repeatedly associated with attacks on schools, hospitals, and other critical organizations, with especially strong reporting on U.S. victims and additional activity affecting the United Kingdom and other countries. The group is notable for using multiple ransomware families rather than relying on a single long-term proprietary locker. Across different periods, Vanilla Tempest and its Vice Society activity have been linked to Hello Kitty/Five Hands, Zeppelin, BlackCat, Quantum Locker, Rhysida, and later INC ransomware. Some reporting describes Vice Society as intrusion, exfiltration, and extortion focused, with double extortion as a core operating model. The actor has also been observed using custom-branded ransomware payloads, including PolyVice, and has shown willingness to rotate third-party payloads as operational needs change. Observed tradecraft includes initial access through exploitation of internet-facing applications, compromised credentials, and socially engineered malware delivery. More recent activity linked to the actor includes SEO-poisoning and trojanized software installers, followed by a shift to ClickFix-style lures on compromised websites. The Lorem Ipsum malware campaign has been attributed with high confidence to Vanilla Tempest and reflects this adaptation: staged loaders, encrypted payloads, dead-drop command-and-control discovery, persistence via DLL sideloading, and handoff to established post-exploitation tooling culminating in ransomware deployment. Microsoft also linked Vanilla Tempest to abuse of malware-signing services used to make malicious installers and payloads appear legitimate. Post-compromise behavior attributed to the actor includes internal reconnaissance, credential theft, privilege escalation, lateral movement, persistence, defense evasion, data exfiltration, and ransomware deployment. Reporting ties the group to use of Cobalt Strike, PowerShell-based tooling, SystemBC, PowerShell Empire, WMI, RDP, scheduled tasks, compromised administrator accounts, and credential-access tools such as Mimikatz and Rubeus. The actor has also been observed disabling security controls, deleting shadow copies, clearing logs, using DLL sideloading and process injection, and abusing legitimate remote-management or file-transfer tools during intrusions. Vice Society activity has been characterized by disproportionate targeting of the education sector, especially K-12 and higher education, where incidents have caused network outages, canceled school days, delayed exams, and exposure of sensitive student information. Health care has also been a recurring focus, including later reporting that Vanilla Tempest deployed INC ransomware against U.S. health care organizations. Manufacturing and IT organizations have likewise appeared in victimology. The actor’s operations are consistently assessed as financially motivated, centered on extortion through encryption and threatened publication of stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
The TTPs are nothing new. They include initial network access through compromised credentials, exploitation of known vulnerabilities (e.g., PrintNightmare)
"Zerologon is a critical-severity privilege escalation vulnerability in Microsoft’s Netlogon Remote Protocol (CVE-2020-1472, patched 11 August 2020), which attackers can exploit to gain administrative access to a Windows domain controller without any authentication"
61 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among detected threat actors/TTP references, but not substantively discussed in the report summary.
Threat actor observed deploying INC ransomware against the health care industry and known for rotating among third-party ransomware payloads.
Financially motivated threat actor behind the Lorem Ipsum ecosystem. Uses ClickFix delivery chains and established post-exploitation tooling, culminating primarily in Rhysida ransomware deployment, and is also associated with BlackCat, Zeppelin, and Quantum Locker.
Financially motivated cybercriminal group linked to the Lorem Ipsum campaign and broader ransomware/data extortion activity. The group is associated with multiple ransomware families and post-exploitation activity following initial access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.