Vectra is the operator and developer of VectraRAT, a rental-only malware-as-a-service platform for Windows systems. Previously known as Nyxel, Vectra markets subscriptions that provide customers access to a Linux-based control server, Windows implant, payload builder, and support channel while retaining the platform source code. The actor has advertised the service through Russian-speaking cybercrime forums and Telegram; a Mandarin-language development environment has been suggested by technical artifacts, but Vectra's nationality is unconfirmed. VectraRAT combines remote-access and information-stealing functions. It supports hidden virtual-desktop access, remote command execution through Command Prompt and PowerShell, screen capture, keylogging, file transfer, process discovery, SOCKS5 proxying, browser-credential collection, and automated collection of network information and configuration files that may contain API keys or database connection strings. It can alter clipboard contents to hijack cryptocurrency addresses and includes an option to bypass UAC and obtain elevated execution without a user prompt. The platform uses a proprietary TCP-based command-and-control protocol and permits operators to redirect deployed implants to replacement control infrastructure. Observed distribution has included Amadey loader deployments and ClickFix social-engineering pages impersonating TurboTax that persuade victims to execute attacker-supplied commands. Victim telemetry showed confirmed file theft and a substantial proportion of affected systems running corporate Windows editions, including enterprise and server deployments. VectraRAT activity is associated with financially motivated malware-service operations rather than a confirmed state-sponsored intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Develops and rents the VectraRAT Windows remote-access malware platform as a malware-as-a-service offering. Subscribers can conduct persistent access, surveillance, credential and data theft, command execution, file transfers, proxying, and privilege escalation against victim systems.
Operates a rental-only malware service offering VectraRAT, a Windows remote-access platform that enables customers to establish persistent access, steal credentials and data, execute commands, transfer files, keylog victims, and proxy traffic through compromised endpoints.
Developer and operator of the VectraRAT rental-only malware-as-a-service platform. The actor provides a custom RAT/stealer platform, payload builder, licensing, support, and crypting services to buyers, whose campaigns distribute the malware through Amadey and ClickFix delivery chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.