SentinelOne reported that the Vice Society ransomware group used a custom-branded locker dubbed PolyVice in intrusions, indicating the group may be sourcing malware from an external specialist rather than relying solely on in-house development. The malware encrypts files across local disks, remote drives, and network shares, and uses a hybrid cryptographic design combining NTRUEncrypt to protect keys with ChaCha20-Poly1305 for per-file encryption, alongside multithreaded routines intended to speed large-scale encryption.
Researchers found code and functionality overlaps linking PolyVice to the RedAlert Linux ransomware and other custom-branded payloads associated with groups including Chily and SunnyDay. The findings point to a broader ransomware-market trend in which affiliates and intrusion groups obtain tailored lockers from third-party developers, expanding the availability of high-performance ransomware tooling across multiple threat actors.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
SentinelOne published analysis of a custom-branded ransomware variant dubbed PolyVice that had been adopted by the Vice Society group in recent intrusions. The report said code overlaps suggest the locker was likely produced by an external specialist developer also linked to RedAlert, Chily, and SunnyDay payloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 28 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.