Vanilla Tempest is a financially motivated cybercriminal threat actor tracked under aliases including DEV-0832, Vice Society, Vice Spider, and Rapid Brigantine. The actor is best known for ransomware and data-extortion operations and has been associated over time with multiple ransomware families, including Vice Society-branded payloads, Zeppelin, HelloKitty/Five Hands, Rhysida, BlackCat, Quantum Locker, and later INC ransomware activity. Reporting also links the actor to the Lorem Ipsum malware ecosystem, indicating continued adaptation in delivery and access methods. The group emerged in 2021 and became notable for disproportionately targeting education and health care organizations, including K-12 institutions, universities, hospitals, and related public-sector entities, while also affecting manufacturing, retail, legal, technology, transportation, and other sectors. Victimology has shown a strong concentration in the United States and the United Kingdom, with additional activity reported across Europe and the Americas. The actor has shown little evidence of sector-based restraint and has been willing to target sensitive organizations such as schools and hospitals. Vanilla Tempest conducts double-extortion operations, stealing data prior to encryption and threatening public release to pressure victims into paying. Its tradecraft includes exploitation of internet-facing applications and known vulnerabilities, abuse of compromised credentials and remote access, phishing and social-engineering-based initial access, and use of commodity and legitimate administrative tooling during post-compromise operations. Observed tooling and behaviors include Cobalt Strike, PowerShell, credential theft utilities, reconnaissance and lateral movement via WMI, SMB, RDP, PsExec, and other living-off-the-land techniques; persistence through scheduled tasks and autostart mechanisms; defense evasion through log clearing, shadow-copy deletion, masquerading, and in some cases DLL side-loading and process injection. The actor has also exfiltrated data before encryption and used leak-site publication as a coercive mechanism. A defining characteristic of Vanilla Tempest is operational flexibility rather than reliance on a single bespoke locker. Earlier Vice Society activity was assessed as focused on gaining access and deploying ransomware obtained from other criminal sources, including Zeppelin and HelloKitty/Five Hands. Later reporting indicates adoption of custom-branded payloads such as PolyVice and use of third-party or externally developed lockers, suggesting a service-based or modular operating model. Multiple reports also assess a relationship between Vice Society and Rhysida, potentially reflecting rebranding, operator overlap, or migration to new ransomware tooling, although definitive proof of a full rebrand remains unconfirmed. By 2024 and 2026, the actor was further linked to INC ransomware deployments, especially against U.S. health care organizations, and to the Lorem Ipsum loader and backdoor campaign. In that campaign, the actor used trojanized installers and later ClickFix-style lures on compromised websites to deliver staged malware through PowerShell execution, Node.js-based components, encrypted payloads, persistence via DLL side-loading, and dead-drop command-and-control techniques before handing off to established post-exploitation workflows and ransomware deployment. Microsoft also identified Vanilla Tempest as a user of malware-signing services provided by Fox Tempest and named it as a co-conspirator in legal action tied to fraudulent code-signing abuse. Overall, Vanilla Tempest is a mature ransomware and extortion actor distinguished by opportunistic targeting, repeated focus on education and health care, reliance on adaptable intrusion tradecraft, and willingness to cycle among ransomware families and delivery mechanisms to sustain operations and evade disruption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Exploiting publicly available vulnerabilities (such as PrintNightmare) to perform remote code execution seems to be the most advanced technique the group has been observed using.
"Zerologon is a critical-severity privilege escalation vulnerability in Microsoft’s Netlogon Remote Protocol (CVE-2020-1472, patched 11 August 2020), which attackers can exploit to gain administrative access to a Windows domain controller without any authentication"
62 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation claiming responsibility for attacks against Spar store operators and leaking allegedly stolen victim data on its data leak site.
Listed among detected threat actors/TTP references, but not substantively discussed in the report summary.
Threat actor observed deploying INC ransomware against the health care industry and known for rotating among third-party ransomware payloads.
Financially motivated threat actor behind the Lorem Ipsum ecosystem. Uses ClickFix delivery chains and established post-exploitation tooling, culminating primarily in Rhysida ransomware deployment, and is also associated with BlackCat, Zeppelin, and Quantum Locker.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.