HackerFeeds
All ransomware groups

vicesociety

188 tracked victims
·first seen 2021-05-31·last activity 2023-06-20

Group profile

Vice Society ransomware appends the .v-society extension when encrypting Linux machines. Running a leak site on the darkweb, Possible relations with "HelloKitty"

MITRE ATT&CK TTPs

TA0001

Initial Access

  • T1078Valid Accounts

    Compromised credentials obtained via phishing or credential markets used to authenticate to victim systems via RDP or VPN.

  • T1190Exploit Public-Facing Application

    Vice Society exploited PrintNightmare (CVE-2021-1675/CVE-2021-34527) and other publicly disclosed vulnerabilities in internet-facing systems as a primary initial access vector.

TA0002

Execution

  • T1059.001Command and Scripting Interpreter: PowerShell

    PowerShell used for payload execution, post-exploitation activity, and lateral movement.

  • T1059.003Command and Scripting Interpreter: Windows Command Shell

    cmd.exe used for executing commands and batch scripts during intrusion.

TA0004

Privilege Escalation

  • T1068Exploitation for Privilege Escalation

    PrintNightmare exploited for local privilege escalation to SYSTEM and for lateral movement via Windows Print Spooler.

TA0005

Defense Evasion

  • T1070.001Indicator Removal: Clear Windows Event Logs

    Event logs cleared using wevtutil to remove forensic artifacts.

  • T1562.001Disable or Modify Tools

    AV and EDR solutions disabled via PowerShell and registry modifications before payload deployment.

TA0006

Credential Access

  • T1003.001OS Credential Dumping: LSASS Memory

    Mimikatz used for credential dumping from LSASS memory.

  • T1003.003OS Credential Dumping: NTDS

    NTDS.dit extracted using ntdsutil or VSS to harvest domain credentials.

TA0007

Discovery

  • T1046Network Service Discovery

    Network scanning to enumerate hosts and services within the victim environment.

TA0008

Lateral Movement

  • T1021.001Remote Services: Remote Desktop Protocol

    RDP used for lateral movement with harvested credentials.

  • T1021.002Remote Services: SMB/Windows Admin Shares

    SMB and PsExec used to propagate payloads and move laterally across the network.

TA0010

Exfiltration

  • T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage

    Data exfiltrated using Rclone and MegaSync to cloud storage for double extortion.

TA0011

Command and Control

  • T1219Remote Access Software

    SystemBC RAT and legitimate remote access tools used for persistent C2.

TA0040

Impact

  • T1486Data Encrypted for Impact

    Vice Society deploys third-party ransomware payloads (HelloKitty, Zeppelin, RedAlert, QuantumLocker, and custom 'ViceSociety' encryptor). Heavily targets the education and healthcare sectors. Double extortion via dedicated leak site.

  • T1490Inhibit System Recovery

    Shadow copies deleted and backup services disabled to prevent recovery.

Recent victims

showing 50 of 188
DateWebsite / victimSectorCountry
2023-06-20
ssv-architekten.de
SSV Architectsssv-architekten.de/
ConstructionDE
2023-06-13TechnologySE
2023-06-04Telecommunication
2023-05-29
ads.dk
Adsbollads.dk/
ConstructionDK
2023-05-22Financial ServicesFR
2023-05-17
antam.com
Aneka Tambangantam.com
EnergyID
2023-05-11TechnologySK
2023-05-02
brightonhill.hants.sch.uk
Brighton Hill Community Schoolbrightonhill.hants.sch.uk/
EducationGB
2023-04-30Manufacturing
2023-04-22
neptunelines.com
Neptune Linesneptunelines.com
Transportation/Logistics
2023-04-18
lakelandcc.edu
Lakeland Community Collegelakelandcc.edu/
EducationUS
2023-04-15Telecommunication
2023-03-31
lclark.edu
Lewis & Clark Collegelclark.edu/
EducationUS
2023-03-23
acueductospr.com
Autoridad de Acueductos Y Alcantarilladosacueductospr.com
Public Sector
2023-03-17
ecolog-international.com
Ecolog Internationalecolog-international.com
Business Services
2023-03-11
berkeleycountyschools.org
Berkeley County Schoolsberkeleycountyschools.org/
Education
2023-03-06
kventa.hu
Kventa Kftkventa.hu/
TechnologyHU
2023-03-05
haw-hamburg.de
HAW Hamburghaw-hamburg.de/
EducationDE
2023-03-03EnergyES
2023-03-01Manufacturing
2023-02-09
msmc.edu
Mount Saint Mary Collegemsmc.edu/
EducationDM
2023-02-01
guildfordcounty.co.uk
Guildford County Schoolguildfordcounty.co.uk/
EducationGB
2023-01-31
semiconductor.com
TechInsightssemiconductor.com
Technology
2023-01-31
sib.it
Societa Italiana Brevetti SpAsib.it/
Business ServicesIT
2023-01-30
okanagan.bc.ca
Okanagan Collegeokanagan.bc.ca/
EducationCA
2023-01-30
scheppers-wetteren.be
Scheppersinstituut Wetterenscheppers-wetteren.be/
EducationBE
2023-01-29
nptcgroup.ac.uk
NPTC Group of Collegesnptcgroup.ac.uk/
EducationGB
2023-01-28
segurosequinoccial.com
Seguros Equinoccialsegurosequinoccial.com
Financial ServicesEC
2023-01-28TelecommunicationAT
2023-01-26
bristolcc.edu
Bristol Community Collegebristolcc.edu/
EducationUS
2023-01-23
emoneyhomeloans.com.au
emoney Home Loansemoneyhomeloans.com.au/
Financial ServicesAU
2023-01-23TechnologyAU
2023-01-20
monmouthcollege.edu
Monmouth Collegemonmouthcollege.edu/
EducationUS
2023-01-16
uni-due.de
University of Duisburg-Essenuni-due.de/
EducationDE
2023-01-14Business ServicesGB
2023-01-14
ctcd.edu
Central Texas Collegectcd.edu/
EducationUS
2023-01-10
frv.vic.gov.au
Fire Rescue Victoriafrv.vic.gov.au
Public SectorAU
2023-01-07
dfp.com.ph
Duty Free Philippinesdfp.com.ph/
Consumer ServicesPH
2023-01-07EducationGB
2023-01-06EducationGB
2023-01-06
bart.gov
Bay Area Rapid Transitbart.gov/
Transportation/LogisticsUS
2023-01-06EducationGB
2023-01-06
proquinal.com
PROQUINAL Spradling Groupproquinal.com
Manufacturing
2023-01-06
sub-drill.com
Sub-drill Supplysub-drill.com
Energy
2023-01-06
letmerepair.com
LetMeRepairletmerepair.com
Business Services
2022-12-20
F
FREDERICK Public Schools
Education
2022-12-20
M
McNamara & Thiel Insurance Agency
Financial Services
2022-12-20
J
JEALSA
Agriculture and Food ProductionES
2022-12-20
C
Communications Solutions Company
TelecommunicationSA
2022-12-20
P
Priority Building Services, LLC
Business Services