Skip to main content

VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch

0
Medium
Published: 09/16/2026 (09/16/2026, 17:03:00 UTC)
Source: AlienVault OTX General

Description

VectraRAT is a previously undocumented Malware-as-a-Service platform combining a Go-based control server (VectraHub) with a native C++ Windows implant, renting from $250 monthly. The developer, operating under the handle 'Vectra' (formerly 'Nyxel'), has been active since August 2022 without prior public documentation. The platform offers hidden desktop control, keylogging, clipboard hijacking with cryptocurrency address replacement, browser credential theft, and a UAC bypass achieving elevation without user prompts. Delivered through Amadey loader and ClickFix campaigns targeting tax-themed lures, 48% of observed victims run corporate Windows editions including Windows Server 2025. Infrastructure analysis revealed exposed directories and operational panels across multiple hosting providers, with victims spanning the United States, Russia, Germany, and other nations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 11:03:33 UTC

Technical Analysis

VectraRAT is a full-stack MaaS platform developed since August 2022, featuring a Go-based control server (VectraHub) and a native C++ implant for Windows. It provides extensive post-compromise capabilities including stealthy desktop control, credential theft, clipboard hijacking targeting cryptocurrency addresses, and a UAC bypass that achieves privilege escalation without user interaction. The malware is distributed through campaigns leveraging Amadey loader and ClickFix, with tax-themed social engineering lures. Analysis of its infrastructure revealed exposed directories and operational panels hosted across various providers. The victimology includes corporate Windows systems, notably Windows Server 2025, across multiple countries including the US, Russia, and Germany.

Potential Impact

The malware enables attackers to gain persistent and stealthy access to infected Windows systems, steal sensitive credentials, hijack clipboard data to redirect cryptocurrency transactions, and escalate privileges without user consent. This can lead to data theft, financial fraud, and unauthorized control over corporate environments. The presence of exposed infrastructure increases the risk of detection and potential disruption of attacker operations.

Defensive Guidance

No official patch or remediation is indicated for this malware platform. Mitigation should focus on detecting and blocking delivery mechanisms such as Amadey loader and ClickFix campaigns, employing endpoint detection and response solutions capable of identifying the implant's behaviors, and restricting privilege escalation paths. Network defenders should monitor for indicators of compromise related to VectraRAT infrastructure and campaigns. Since this is malware-as-a-service, organizations should also maintain strong user awareness to resist social engineering lures like tax-themed phishing.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://socradar.io/blog/vectrarat-undocumented-stack-maas"]
Adversary
Vectra
Pulse Id
6aaacbc43d4293c72220717b

Indicators of Compromise

Ip

ValueDescriptionCopy
ip91.92.242.236
ip178.16.54.148
CC=DE ASN=AS40999 dus.net gmbh

Hash

ValueDescriptionCopy
hash2ed675d3342f069b6ebb090ee8085f43
hash7899b3e9e899acc932c7839d37ef0c74
hash89706fa83374ddd3d52ac569d876ac6a
hasha3dc3ee464737dd74c20ec771deaac4d
hasha8619784bfe927e551e831d4adaf8ba5
hash05a873fcac5373d5c3b24b2541b7b861cc4c5c05
hash1a5f6531962a08b29c8b5f1572383b52434f1428
hash5a68ece20d05c755d20975b4e1794d0f531d2c19
hash69c3e85b5f1fc3b7787147b18e0158db32b0662c
hashdbded25e78aa62d963f676665020917da09d32e5
hash3ab56c9fb6b7c404c1e5b36788959c877ea819fb124c3847fa0498e9915ef9a7
hash7b82f08120e0d9b16cd5b9ec59d24fb68e35735c82311a233d370e7f264af650
hash8745e872ff8aa41b0e03737f76bf35b6c934106c987dff98afe34120e47caf91
hashb738c03fef5e3d26419e4aab1818a0a7ad206c67fb3eeedcdfb3ef1ee07eb620
hashb926cfcd3f4b07fe6001c39f46e40225ff8000411198d13782538d770c54ae5e
hashbba58f99e14e3512c04a5a74a079d7851abf935dd258cff4c80874ce7cfc82e3
hashbff3583d04f0d5603ced9831eb7c45c1923bd90e2f7d5e5d2b32942d38cf6dc5
hashc708d413720848f8788f43a4f47ddce016fca9af10c9ba4113f47bf2c9244dc5
hashd8f15ba122cd6da01f83fe05294df80a6eadbce0f66dac7c2bcc0904f066e0de
hashddbd636f6dfd475dc0c75bf9f6f873fa35b9062dee9d37b3377ae7b9acdcd0c9
hashdede8bfb55c2e6479d89b1e73e0712791cf16a7179325804fc4bc13f708d08ae
hashe2db5db12564d2a9da7ef3a57aa23d95782f5eaddc8bd35eb7c35ae6b844a0f0
hash1d73a2c6c715051cdc5afd51248e96af
hash55748a44b217853f7eda25080045612b
hash92fccba38f921c45917e56db6cf12810
hashadb441372f365dcb1e59bcfc37a4ade8
hashd1cda5a35a2751fc5d7595917c992d65
hash19cec1db30a349e1fa2884f864153fd21a6733c8
hash2269b2690349a57203d6ab9a84828a7ff53b496c
hash798e0fc22b1646783fa65f1cc692fde635c0e5a8
hash7c049c51338b6485abb8368e32b0b09041d3e1d2
hashbcdcde73a38da486a24ebd93a6bdace8579563be
hash2e1b94d5e5d6f71cbc26c25184048729
hash88f548ea59edd3b934a671bd4a09a783
hash9a822848a04915873deac85705d7375900755ae5
hashadcb507c3c3239fdbd62112168fcba3d72fcecfb

Threat ID: 6aabc50d55bf5e2cf53b207c

Added to database: 09/17/2026, 10:46:37 UTC

Last enriched: 09/17/2026, 11:03:33 UTC

Last updated: 09/17/2026, 22:01:24 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses