VectraRAT is an undocumented full-stack Malware-as-a-Service platform built from scratch, not a reskin of existing RAT code. It pairs a Go control server called VectraHub with a Vue3 operator panel and a native C++ Windows implant. The two communicate using a proprietary binary TCP protocol over port 3308. VectraRAT offers hidden desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates without a prompt. Rented for $250 per month, it is delivered through the Amadey loader and ClickFix pages, targeting corporate Windows editions with active exfiltration from Windows Server hosts.
The developer keeps the source code and handles support over Telegram. VectraRAT differs from most remote access tools sold on crimeware forums, which are often borrowed goods or reskinned versions of existing malware. VectraRAT is a rental-only platform that gives operators full remote control of Windows hosts, along with automated credential and file collection on first connection.[/subscribe_to_unlock_form]
VectraRAT is an undocumented full-stack Malware-as-a-Service platform built from scratch, not a reskin of existing RAT code. It pairs a Go control server called VectraHub with a Vue3 operator panel and a native C++ Windows implant. The two communicate using a proprietary binary TCP protocol over port 3308. VectraRAT offers hidden desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates without a prompt. Rented for $250 per month, it is delivered through the Amadey loader and ClickFix pages, targeting corporate Windows editions with active exfiltration from Windows Server hosts.
The developer keeps the source code and handles support over Telegram. VectraRAT differs from most remote access tools sold on crimeware forums, which are often borrowed goods or reskinned versions of existing malware. VectraRAT is a rental-only platform that gives operators full remote control of Windows hosts, along with automated credential and file collection on first connection.[emaillocker id="1283"]
The business model is based on renting access to the platform for $250 per month. VectraRAT's significance lies in its unique development and operation. It has been active since at least, with no prior public reporting. The operator "Vectra" is a rebrand of an older identity, "Nyxel", which has a YouTube channel dating back to. The platform's capabilities span both the RAT and stealer space, making it a significant threat in the cyber landscape.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Discovery | E1083 | File and Directory Discovery |
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Discovery | E1082 | System Information Discovery |
The following reports contain further technical details:
[/emaillocker]