Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
🇲🇾 MY1 malware family

VFVCT

Also known asvfvct

VFVCT, also referred to as V For Vendetta Cyber Team, is a threat actor operating within a broader collaborative cybercrime ecosystem tied to THE PERSEPHONE leak platform. The content links VFVCT to THE PERSEPHONE through a BreachForums post by the user VFVCT that referred to the Persephone domain as "our website," repeated sharing of the domain in VFVCT-linked Telegram channels, and prominent references to VFVCT on the Persephone landing page. THE PERSEPHONE presented itself as a prototype leak platform and described cooperation among VFVCT, RasCorp Group, and ClayRat/CrackRat Zone Clay under the banner of "United Cyber Operations," indicating that VFVCT participated in a multi-group alliance rather than acting solely through a standalone leak site. The group used Telegram channels and groups as a communication and coordination layer for recruitment, leak promotion, operational messaging, and discussion of future database releases. A private Telegram group titled Project_Vendetta referenced V For Vendetta Cyber Team and listed contact points including a Telegram bot and email addresses. A separate Telegram channel presented itself as a backup channel for VFVCT. Messages in these channels discussed hacking activities, recruitment, geopolitical commentary, and upcoming data releases, including a planned database release at the end of Ramadan. One message claimed campaigns targeting South Korea, India, and Indonesia and asserted possession of large datasets associated with those countries. The content also indicates that VFVCT maintained broader supporting infrastructure beyond Telegram, including references to a GitHub Pages site described by the actors as part of their DLS or ransomware-related infrastructure, a TOX ID, a Session messenger ID, and a separate website hosted through a free web hosting provider. A VFVCT channel message invited technically skilled individuals to contact the group regarding ransomware partnerships. Within the alliance described in the content, VFVCT was characterized as contributing operational and strategic capabilities, while RasCorp Group handled business operations and coordination and CrackRat Zone Clay provided multifunctional tools. Known aliases and associated names directly mentioned in the content include VFVCT and V For Vendetta Cyber Team. Associated allied groups mentioned are RasCorp Group and ClayRat/CrackRat Zone Clay.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇮🇱 Israel
  • 🇰🇷 South Korea
  • 🇮🇳 India
  • 🇮🇩 Indonesia

Where they're from

Attributed origin per open-source reporting.

  • MY
MITRE ATT&CK

Tradecraft

6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

5 of 15 tactics7 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1589
Gather Victim Identity Information
TA0042
Resource Development
2 techniques
T1587
Develop Capabilities
T1588
Obtain Capabilities
TA0007
Discovery
1 technique
T1580
Cloud Infrastructure Discovery
TA0011
Command and Control
1 technique
T1071
Application Layer Protocol
TA0010
Exfiltration
1 technique
T1567
Exfiltration Over Web Service
T1567.003
Exfiltration to Text Storage Sites
IOCS

Observables

6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping6

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables6

Domains, IPs, and hashes tied to this actor, refreshed continuously.