Threat Advisory

VectraRAT is a Full-Stack Malware-as-a-Service Platform Built from Scratch

Threat: Malware
Threat Actor Name: Vectra Group (Nyxel)
Targeted Region: United States, Russia, Germany, India, Switzerland, the Czech Republic, Venezuela
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

VectraRAT is an undocumented full-stack Malware-as-a-Service platform built from scratch, not a reskin of existing RAT code. It pairs a Go control server called VectraHub with a Vue3 operator panel and a native C++ Windows implant. The two communicate using a proprietary binary TCP protocol over port 3308. VectraRAT offers hidden desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates without a prompt. Rented for $250 per month, it is delivered through the Amadey loader and ClickFix pages, targeting corporate Windows editions with active exfiltration from Windows Server hosts.

The developer keeps the source code and handles support over Telegram. VectraRAT differs from most remote access tools sold on crimeware forums, which are often borrowed goods or reskinned versions of existing malware. VectraRAT is a rental-only platform that gives operators full remote control of Windows hosts, along with automated credential and file collection on first connection.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

VectraRAT is an undocumented full-stack Malware-as-a-Service platform built from scratch, not a reskin of existing RAT code. It pairs a Go control server called VectraHub with a Vue3 operator panel and a native C++ Windows implant. The two communicate using a proprietary binary TCP protocol over port 3308. VectraRAT offers hidden desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates without a prompt. Rented for $250 per month, it is delivered through the Amadey loader and ClickFix pages, targeting corporate Windows editions with active exfiltration from Windows Server hosts.

The developer keeps the source code and handles support over Telegram. VectraRAT differs from most remote access tools sold on crimeware forums, which are often borrowed goods or reskinned versions of existing malware. VectraRAT is a rental-only platform that gives operators full remote control of Windows hosts, along with automated credential and file collection on first connection.[emaillocker id="1283"]

The business model is based on renting access to the platform for $250 per month. VectraRAT's significance lies in its unique development and operation. It has been active since at least, with no prior public reporting. The operator "Vectra" is a rebrand of an older identity, "Nyxel", which has a YouTube channel dating back to. The platform's capabilities span both the RAT and stealer space, making it a significant threat in the cyber landscape.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1204.002 User Execution Malicious File
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Discovery E1083 File and Directory Discovery
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder
Anti-Static Analysis E1027 Obfuscated Files or Information
Anti-Static Analysis B0032 Executable Code Obfuscation
Discovery E1082 System Information Discovery

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu