Vice Society is a financially motivated ransomware operation first identified in 2021. It is known for double-extortion attacks in which operators exfiltrate victim data before encrypting systems and threaten public release when demands are not met. The operation has disproportionately targeted education and healthcare organizations and has also affected manufacturing, logistics, government, and other enterprise environments across multiple regions.
Vice Society initially deployed third-party ransomware payloads, including HelloKitty/Five Hands, Zeppelin, RedAlert, and related variants. By late 2022, the group was observed using custom ransomware, including a variant referred to as PolyVice. Its operations have targeted Windows and Linux systems, and observed intrusions affected virtualized infrastructure.
Observed Vice Society activity includes initial access through compromised VPN or RDP credentials and exploitation of public-facing services. Affiliates associated with its activity have conducted network and remote-service discovery, credential dumping, Active Directory database theft, account creation, lateral movement through RDP, SSH, and remote execution tools, and data staging and exfiltration before encryption. The operation has also used PrintNightmare and ZeroLogon vulnerabilities in reported intrusions. Defense-evasion behavior includes disabling endpoint protections, terminating security and business processes, deleting shadow copies, clearing event logs, and removing remote-access traces.
Secureworks tracks the Vice Society operation as Gold Victor. Multiple investigations identified an affiliate cluster that transitioned from deploying Vice Society to Rhysida while retaining similar tradecraft, but a definitive Vice Society-to-Rhysida rebrand has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Группа вымогателей Vice Society теперь активно использует уязвимость PrintNightmare (CVE-2021-1675 и CVE-2021-34527) диспетчера очереди печати Windows для бокового перемещения по сетям своих жертв. | Название: Vice Society. Вероятно спин-офф от HelloKitty ... Группа вымогателей Vice Society теперь активно использует уязвимость PrintNightmare (CVE-2021-1675 и CVE-2021-34527).
The situation began in June with CVE-2021-1675 ... There was confusion when researchers published a proof-of-concept (PoC) called “PrintNightmare,” stating it was for CVE-2021-1675 when it was actually a distinct vulnerability.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Название: Vice Society. Вероятно спин-офф от HelloKitty ... Группа вымогателей Vice Society теперь активно использует уязвимость PrintNightmare (CVE-2021-1675 и CVE-2021-34527).
Secureworks calls that group Gold Victor and it operated a ransomware scheme called Vice Society.
"...we identified a ransomware affiliate group move from deploying Vice Society to leveraging Rhysida ransomware in attacks against enterprises."
6 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously disrupted ransomware operation with an assessed, but unconfirmed, tactical or personnel-overlap connection to Rhysida.
A ransomware group known for targeting organizations with human-operated campaigns, exploiting vulnerabilities in unsupported or unpatched Windows systems.
Ransomware strain used in extortion operations.
Ransomware group/family discussed as possibly rebranding to Rhysida after targeting healthcare and education organizations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.