VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch
VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations.
AI Analysis
Technical Summary
VectraRAT is a full-stack MaaS platform developed since August 2022, featuring a Go-based control server (VectraHub) and a native C++ implant for Windows. It provides extensive post-compromise capabilities including stealthy desktop control, credential theft, clipboard hijacking targeting cryptocurrency addresses, and a UAC bypass that achieves privilege escalation without user interaction. The malware is distributed through campaigns leveraging Amadey loader and ClickFix, with tax-themed social engineering lures. Analysis of its infrastructure revealed exposed directories and operational panels hosted across various providers. The victimology includes corporate Windows systems, notably Windows Server 2025, across multiple countries including the US, Russia, and Germany.
Potential Impact
The malware enables attackers to gain persistent and stealthy access to infected Windows systems, steal sensitive credentials, hijack clipboard data to redirect cryptocurrency transactions, and escalate privileges without user consent. This can lead to data theft, financial fraud, and unauthorized control over corporate environments. The presence of exposed infrastructure increases the risk of detection and potential disruption of attacker operations.
Mitigation Recommendations
No official patch or remediation is indicated for this malware platform. Mitigation should focus on detecting and blocking delivery mechanisms such as Amadey loader and ClickFix campaigns, employing endpoint detection and response solutions capable of identifying the implant's behaviors, and restricting privilege escalation paths. Network defenders should monitor for indicators of compromise related to VectraRAT infrastructure and campaigns. Since this is malware-as-a-service, organizations should also maintain strong user awareness to resist social engineering lures like tax-themed phishing.
Affected Countries
United States, Russia, Germany
Indicators of Compromise
- ip: 91.92.242.236
- ip: 178.16.54.148
- hash: 2ed675d3342f069b6ebb090ee8085f43
- hash: 7899b3e9e899acc932c7839d37ef0c74
- hash: 89706fa83374ddd3d52ac569d876ac6a
- hash: a3dc3ee464737dd74c20ec771deaac4d
- hash: a8619784bfe927e551e831d4adaf8ba5
- hash: 05a873fcac5373d5c3b24b2541b7b861cc4c5c05
- hash: 1a5f6531962a08b29c8b5f1572383b52434f1428
- hash: 5a68ece20d05c755d20975b4e1794d0f531d2c19
- hash: 69c3e85b5f1fc3b7787147b18e0158db32b0662c
- hash: dbded25e78aa62d963f676665020917da09d32e5
- hash: 3ab56c9fb6b7c404c1e5b36788959c877ea819fb124c3847fa0498e9915ef9a7
- hash: 7b82f08120e0d9b16cd5b9ec59d24fb68e35735c82311a233d370e7f264af650
- hash: 8745e872ff8aa41b0e03737f76bf35b6c934106c987dff98afe34120e47caf91
- hash: b738c03fef5e3d26419e4aab1818a0a7ad206c67fb3eeedcdfb3ef1ee07eb620
- hash: b926cfcd3f4b07fe6001c39f46e40225ff8000411198d13782538d770c54ae5e
- hash: bba58f99e14e3512c04a5a74a079d7851abf935dd258cff4c80874ce7cfc82e3
- hash: bff3583d04f0d5603ced9831eb7c45c1923bd90e2f7d5e5d2b32942d38cf6dc5
- hash: c708d413720848f8788f43a4f47ddce016fca9af10c9ba4113f47bf2c9244dc5
- hash: d8f15ba122cd6da01f83fe05294df80a6eadbce0f66dac7c2bcc0904f066e0de
- hash: ddbd636f6dfd475dc0c75bf9f6f873fa35b9062dee9d37b3377ae7b9acdcd0c9
- hash: dede8bfb55c2e6479d89b1e73e0712791cf16a7179325804fc4bc13f708d08ae
- hash: e2db5db12564d2a9da7ef3a57aa23d95782f5eaddc8bd35eb7c35ae6b844a0f0
- hash: 1d73a2c6c715051cdc5afd51248e96af
- hash: 55748a44b217853f7eda25080045612b
- hash: 92fccba38f921c45917e56db6cf12810
- hash: adb441372f365dcb1e59bcfc37a4ade8
- hash: d1cda5a35a2751fc5d7595917c992d65
- hash: 19cec1db30a349e1fa2884f864153fd21a6733c8
- hash: 2269b2690349a57203d6ab9a84828a7ff53b496c
- hash: 798e0fc22b1646783fa65f1cc692fde635c0e5a8
- hash: 7c049c51338b6485abb8368e32b0b09041d3e1d2
- hash: bcdcde73a38da486a24ebd93a6bdace8579563be
- hash: 2e1b94d5e5d6f71cbc26c25184048729
- hash: 88f548ea59edd3b934a671bd4a09a783
- hash: 9a822848a04915873deac85705d7375900755ae5
- hash: adcb507c3c3239fdbd62112168fcba3d72fcecfb
VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch
Description
VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
VectraRAT is a full-stack MaaS platform developed since August 2022, featuring a Go-based control server (VectraHub) and a native C++ implant for Windows. It provides extensive post-compromise capabilities including stealthy desktop control, credential theft, clipboard hijacking targeting cryptocurrency addresses, and a UAC bypass that achieves privilege escalation without user interaction. The malware is distributed through campaigns leveraging Amadey loader and ClickFix, with tax-themed social engineering lures. Analysis of its infrastructure revealed exposed directories and operational panels hosted across various providers. The victimology includes corporate Windows systems, notably Windows Server 2025, across multiple countries including the US, Russia, and Germany.
Potential Impact
The malware enables attackers to gain persistent and stealthy access to infected Windows systems, steal sensitive credentials, hijack clipboard data to redirect cryptocurrency transactions, and escalate privileges without user consent. This can lead to data theft, financial fraud, and unauthorized control over corporate environments. The presence of exposed infrastructure increases the risk of detection and potential disruption of attacker operations.
Defensive Guidance
No official patch or remediation is indicated for this malware platform. Mitigation should focus on detecting and blocking delivery mechanisms such as Amadey loader and ClickFix campaigns, employing endpoint detection and response solutions capable of identifying the implant's behaviors, and restricting privilege escalation paths. Network defenders should monitor for indicators of compromise related to VectraRAT infrastructure and campaigns. Since this is malware-as-a-service, organizations should also maintain strong user awareness to resist social engineering lures like tax-themed phishing.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://socradar.io/blog/vectrarat-undocumented-stack-maas"]
- Adversary
- Vectra
- Pulse Id
- 6aaacbc43d4293c72220717b
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip91.92.242.236 | — | |
ip178.16.54.148 | CC=DE ASN=AS40999 dus.net gmbh |
Hash
| Value | Description | Copy |
|---|---|---|
hash2ed675d3342f069b6ebb090ee8085f43 | — | |
hash7899b3e9e899acc932c7839d37ef0c74 | — | |
hash89706fa83374ddd3d52ac569d876ac6a | — | |
hasha3dc3ee464737dd74c20ec771deaac4d | — | |
hasha8619784bfe927e551e831d4adaf8ba5 | — | |
hash05a873fcac5373d5c3b24b2541b7b861cc4c5c05 | — | |
hash1a5f6531962a08b29c8b5f1572383b52434f1428 | — | |
hash5a68ece20d05c755d20975b4e1794d0f531d2c19 | — | |
hash69c3e85b5f1fc3b7787147b18e0158db32b0662c | — | |
hashdbded25e78aa62d963f676665020917da09d32e5 | — | |
hash3ab56c9fb6b7c404c1e5b36788959c877ea819fb124c3847fa0498e9915ef9a7 | — | |
hash7b82f08120e0d9b16cd5b9ec59d24fb68e35735c82311a233d370e7f264af650 | — | |
hash8745e872ff8aa41b0e03737f76bf35b6c934106c987dff98afe34120e47caf91 | — | |
hashb738c03fef5e3d26419e4aab1818a0a7ad206c67fb3eeedcdfb3ef1ee07eb620 | — | |
hashb926cfcd3f4b07fe6001c39f46e40225ff8000411198d13782538d770c54ae5e | — | |
hashbba58f99e14e3512c04a5a74a079d7851abf935dd258cff4c80874ce7cfc82e3 | — | |
hashbff3583d04f0d5603ced9831eb7c45c1923bd90e2f7d5e5d2b32942d38cf6dc5 | — | |
hashc708d413720848f8788f43a4f47ddce016fca9af10c9ba4113f47bf2c9244dc5 | — | |
hashd8f15ba122cd6da01f83fe05294df80a6eadbce0f66dac7c2bcc0904f066e0de | — | |
hashddbd636f6dfd475dc0c75bf9f6f873fa35b9062dee9d37b3377ae7b9acdcd0c9 | — | |
hashdede8bfb55c2e6479d89b1e73e0712791cf16a7179325804fc4bc13f708d08ae | — | |
hashe2db5db12564d2a9da7ef3a57aa23d95782f5eaddc8bd35eb7c35ae6b844a0f0 | — | |
hash1d73a2c6c715051cdc5afd51248e96af | — | |
hash55748a44b217853f7eda25080045612b | — | |
hash92fccba38f921c45917e56db6cf12810 | — | |
hashadb441372f365dcb1e59bcfc37a4ade8 | — | |
hashd1cda5a35a2751fc5d7595917c992d65 | — | |
hash19cec1db30a349e1fa2884f864153fd21a6733c8 | — | |
hash2269b2690349a57203d6ab9a84828a7ff53b496c | — | |
hash798e0fc22b1646783fa65f1cc692fde635c0e5a8 | — | |
hash7c049c51338b6485abb8368e32b0b09041d3e1d2 | — | |
hashbcdcde73a38da486a24ebd93a6bdace8579563be | — | |
hash2e1b94d5e5d6f71cbc26c25184048729 | — | |
hash88f548ea59edd3b934a671bd4a09a783 | — | |
hash9a822848a04915873deac85705d7375900755ae5 | — | |
hashadcb507c3c3239fdbd62112168fcba3d72fcecfb | — |
Threat ID: 6aabc50d55bf5e2cf53b207c
Added to database: 09/17/2026, 10:46:37 UTC
Last enriched: 09/17/2026, 11:03:33 UTC
Last updated: 09/17/2026, 22:01:24 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.