VanHelsing is a ransomware-as-a-service operation that emerged in March 2025 and provides a multi-platform file-encrypting malware family for affiliate use. It is primarily documented as targeting Windows, with additional advertised support for Linux, BSD, ARM-based environments, and VMware ESXi. The operation follows the common double-extortion model by encrypting victim data while also operating a leak site used to pressure victims with the threat of publishing stolen information. Public reporting indicates the group explicitly prohibits attacks against Russian and other CIS-linked organizations, a pattern consistent with parts of the Russian-speaking cybercrime ecosystem.
On Windows, VanHelsing encrypts files and has been observed appending variants such as .vanhelsing and .vanlocker to affected data. It drops a ransom note named README.txt, changes the victim desktop wallpaper, and directs victims to Tor-based negotiation infrastructure. The malware excludes selected system-critical files, extensions, and directories from encryption to preserve system operability, and it creates a mutex associated with its family name. Reported command-line options indicate configurable execution behavior, including reduced logging and options suggestive of operation across local and remote resources. The family has also been associated with shadow copy deletion and process hollowing or similar process-injection tradecraft intended to inhibit recovery and reduce detection.
VanHelsing has been linked to attacks affecting organizations in multiple countries, including the United States, Italy, France, and Australia, with manufacturing among the most represented victim sectors in early observed leak-site postings. At least one municipal government victim has also been reported, indicating broad opportunistic targeting rather than a narrow industry focus. Reporting on initial access remains limited, though lateral movement via administrative tooling has been associated with the operation in some analyses.
The operation gained additional attention after source code related to its affiliate panel, leak blog, and Windows builder was publicly released following an internal dispute involving a former developer. The leak raised concern about copycat campaigns and downstream reuse, as has occurred previously with other leaked ransomware builders. VanHelsing operators subsequently indicated plans to continue development under a newer version.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Affiliates are individuals or groups that collaborate with RaaS operators to perform actions such as initial penetration, network lateral movement, data exfiltration, and ransomware distribution.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a ransomware collective that prohibits attacks on Russian-linked targets.
Ransomware-as-a-service group referenced as enforcing a rule against targeting Russian and CIS entities.
Associated Analytic Story Cactus Ransomware DarkGate Malware DarkSide Ransomware Ransomware Revil Ransomware VanHelsing Ransomware
Named ransomware family referenced in associated analytic stories connected to shadow copy manipulation behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.