Ink ransomware is a ransomware payload observed in use by the financially motivated threat actor Vanilla Tempest, also known as Vice Society/Vice Spider and previously tracked by Microsoft as DEV-0832. Microsoft stated it first observed Vanilla Tempest using Ink ransomware during attacks against U.S. hospitals in August 2024, marking the first time the group had been seen deploying Ink. The actor is described as conducting ransomware operations involving data exfiltration and extortion.
Within the provided reporting, Ink is one of several ransomware families used by Vanilla Tempest, alongside BlackCat, Quantum/QuantumLocker, Zeppelin/Zeplin, and Recita. Vanilla Tempest tradecraft associated with these operations includes use of PowerShell scripts, repurposed legitimate tools, exploitation of publicly disclosed vulnerabilities for initial access, and backdoors such as SystemBC and Supper. Microsoft also linked Vanilla Tempest to GootLoader infections delivered via SEO poisoning, where users are lured through search results to actor-controlled content; in the described chain, GootLoader creates a scheduled task that runs JavaScript and launches PowerShell, after which activity is handed off to Vanilla Tempest for hands-on-keyboard intrusion. The content also notes use of tools including AnyDesk and Mega.
High-confidence targeting information in the content indicates Vanilla Tempest used Ink ransomware in attacks targeting hospitals in the United States. No specific file hashes, domains, IP addresses, ransom note names, or other Ink-specific indicators of compromise were provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware payload used by Vanilla Tempest for data extortion; Microsoft observed a shift to Ink in Aug 2024 during attacks against US hospitals.
Ransomware used in Vanilla Tempest campaigns; described here as targeting hospitals in prior activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.