SOCRadar researchers have identified VectraRAT, an undocumented Malware-as-a-Service (MaaS) platform targeting Windows enterprise environments for a $250 monthly subscription. Unlike many competitors that use leaked or forked code, VectraRAT was built entirely from scratch, featuring a custom Windows implant, a Linux-based command-and-control (C2) infrastructure, and a proprietary communication protocol.
The malware provides a suite of advanced features including UAC bypass, hidden desktop access, keylogging, and automatic credential harvesting from browsers and configuration files. Delivery typically occurs through social engineering via ClickFix pages or the Amadey loader. Data suggests a focus on high-value corporate targets, with nearly half of its victims running enterprise-grade versions of Windows and Windows Server.
Top comments (0)