VectraRAT is a Windows-focused, rental-only malware-as-a-service remote-access trojan operated by a developer known as Vectra, reportedly formerly Nyxel. The platform comprises a Windows implant, a Linux-based control server, an operator panel, and a payload builder. It provides covert remote control through a hidden virtual desktop, screen capture, remote Command Prompt and PowerShell execution, file transfer, process discovery, keylogging, and SOCKS5 proxying through compromised hosts. Its automated collection component gathers browser credentials, network and system information, and configuration files that can contain sensitive application secrets. VectraRAT can also manipulate clipboard contents to hijack cryptocurrency payment addresses and supports privilege escalation without a user prompt through abuse of trusted Windows auto-elevation functionality. The implant uses a custom TCP command-and-control protocol and can be redirected to new control infrastructure after deployment. Observed distribution included Amadey-mediated deployment and ClickFix social-engineering pages, including tax-themed lures that induced victims to execute attacker-supplied commands. Activity has affected corporate Windows environments, including Enterprise and Windows Server systems, and has included theft of files from business systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VectraRAT is a rental-only Malware-as-a-Service platform that gives a paying operator full remote control of a Windows host, along with automated credential and file collection on first connection.
VectraRAT is a rental-only Malware-as-a-Service platform that gives a paying operator full remote control of a Windows host, along with automated credential and file collection on first connection.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Once installed, the implant can ... run Command Prompt or PowerShell.
Once installed, the implant can ... run Command Prompt or PowerShell.
The UAC bypass uses undocumented ntdll functions including NtQueryInformationProcess, NtRemoveProcessDebug, NtDuplicateObject, and DbgUiSetThreadDebugObject.
ClickFix [is] the fake CAPTCHA technique that convinces a user to paste and run a command themselves.
The stub builder customizes PE VERSIONINFO metadata and recalculates the PE checksum through ApplyStubPE.ForceCheckSum and ApplyStubPE.WithAuthenticode from Linux.
Stubs have been distributed with tax-related naming such as TurboTax2026.exe to reduce user suspicion in North American campaigns during tax season.
It also collects browser credentials, network details and configuration files containing possible API keys or database strings when it first connects.
The netstat module of DataCollect captures active network connections as part of initial automated collection.
“Researchers recorded 38 genuine victim sessions in less than a week, with evidence of file theft from business systems.”
The [ImageSender] module captures desktop frames through GDI+, compresses them with LZNT1, and transmits raw RGB data to the hub.
The malware gives paying operators a way to ... move traffic through an infected computer.
A SOCKS5 relay turns the compromised host into an egress node, identified internally as 'Slave' in the hub code.
The malware uses a custom TCP-based communication method over a non-standard channel rather than normal web traffic.
“Researchers observed buyers delivering VectraRAT through Amadey and through ClickFix lures” and the implant can “transfer files.”
VectraRAT is a Windows-focused remote access tool ... [that enables operators] to watch victims, steal data, run commands, and move traffic through an infected computer.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rental-only Windows remote-access malware platform providing hidden-desktop access, keylogging, command execution, file transfer, proxying, browser-credential theft, reconnaissance, configuration/API-key collection, callback-address updates, and a privilege-escalation option. It uses a custom TCP command-and-control protocol, with TCP/3308 identified as its C2 port.
Windows remote-access trojan offered as a malware-as-a-service subscription for $250 per month. It provides persistent remote control, hidden desktop access, command execution, keylogging, file transfer and theft, browser-credential and configuration collection, proxying, callback-address updates, and a privilege-escalation capability.
A custom full-stack Windows RAT and information stealer operated as a rental MaaS. It provides HVNC/hidden-desktop control, remote CMD or PowerShell shell access, keylogging, clipboard monitoring and cryptocurrency-address replacement, SOCKS5 proxying, file transfer, process enumeration, screen capture, and automated collection of browser credentials, network connections, and secret-bearing configuration files. It includes a UAC-bypass chain equivalent to UACME #41 that obtains High Integrity execution without a user prompt.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.