Thor is a ransomware threat group first observed targeting Russian companies in 2025. It has used LockBit and Babuk ransomware payloads and has been associated with pro-Ukrainian hacking activity. Thor has exploited exposed Microsoft SharePoint Server and Ivanti vulnerabilities for initial access. Its operations use publicly available and dual-use tools for network reconnaissance, privilege escalation, credential dumping, data collection, persistence, and exfiltration. Observed tooling includes remote-management software for persistence and Rclone for data transfer. Thor activity has been reported primarily against Russian organizations; in one investigated intrusion, early detection prevented ransomware deployment. F6 has assessed that VantaCore may be a rebrand of Thor, but this linkage remains an assessment rather than a confirmed identity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A pro-Ukrainian ransomware operation assessed as the predecessor or rebranded identity of VantaCore. Its 2025 operations against Russia combined financial extortion with destructive or politically motivated activity.
Thor is a threat group involved in ransomware attacks against Russian companies, deploying ransomware and remote management tools for persistence.
Thor is a financially motivated threat group targeting Russian organizations with ransomware and related tools, focusing on data theft and extortion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.