Researchers uncovered VectraRAT, a previously undocumented Windows remote-access trojan sold exclusively as a malware-as-a-service subscription for $250 per month. Operated by a developer using the aliases Vectra and formerly Nyxel, the full-stack platform enables surveillance, credential theft, remote command execution, file transfer, proxying, and privilege escalation on compromised systems.
SOCRadar discovered the operation through an exposed directory containing malware samples, server-side components, licenses, and operator logs, then identified more than 10 related servers. Operators delivered VectraRAT through Amadey loader campaigns and ClickFix pages impersonating TurboTax that prompt victims to paste commands into the Windows Run dialog; logs showed 38 genuine sessions in less than a week, with corporate Windows editions—including Enterprise and Windows Server 2025—accounting for 48% of records containing operating-system data.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
SOCRadar attributed the VectraRAT service to an operator known as Vectra, previously Nyxel, and identified exposed command-and-control, operator-panel, ClickFix, and Amadey-related infrastructure. The analysis documented a custom TCP C2 protocol on port 3308, configurable post-infection callback addresses, and abuse of Windows auto-elevation utilities for elevated execution.
Researchers identified VectraRAT as a previously undocumented, Windows-focused remote-access trojan rented as a malware-as-a-service platform for $250 per month. They observed delivery via Amadey and TurboTax-themed ClickFix lures, and recorded 38 genuine victim sessions in under a week, including evidence of file theft from business systems.
SOCRadar's Threat Research Unit began investigating on June 23 after finding an exposed directory containing VectraRAT samples, server components, licenses, and operator logs. The investigation expanded to more than ten related servers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.