Rapid Brigantine, also known as Vice Society, GOLD VICTOR, Vanilla Tempest, DEV-0832, and VICE SPIDER, is a financially motivated cybercriminal threat group active since at least mid-2022. It has deployed ransomware families including Rhysida, BlackCat, Zeppelin, and Quantum Locker. The group operates the Lorem Ipsum Loader ecosystem, which uses SEO-poisoned websites and trojanized Microsoft Teams installers, as well as ClickFix-style browser-update lures that persuade users to execute malicious PowerShell commands in Windows Terminal. Its delivery chains abuse legitimate Microsoft executables for DLL sideloading and legitimate Node.js and Python runtimes to execute malicious components. Payloads are concealed using word-based encoding, while anti-debugging checks, sandbox detection, hidden execution, and long delays impede analysis. Lorem Ipsum Loader obtains command-and-control locations through encoded data in attacker-controlled social-platform profiles and exchanges encoded communications disguised as JPEG images. Associated tooling supports PowerShell execution, host and Active Directory reconnaissance, persistence through autorun entries and scheduled tasks, and encrypted WebSocket reverse tunnels that relay traffic through compromised hosts. Persistence components masquerade as legitimate Microsoft or software-update components. Ransomware encryption has not been observed in the associated STAC4924 campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercriminal group attributed by BlueVoyant to the Lorem Ipsum Loader activity and assessed by Sophos to be connected to STAC4924. The group has been linked to the Vice Society and Rhysida ransomware families, although Sophos did not observe encryption during the STAC4924 activity.
A cybercriminal threat group linked to the Vice Society and Rhysida ransomware families. BlueVoyant attributed Lorem Ipsum Loader to this group, and Sophos reports that STAC4924 tooling, infrastructure, and delivery changes support that attribution. Attribution is supported rather than conclusively established, and Sophos observed no encryption in STAC4924.
Financially motivated intrusion group assessed as operating the Lorem Ipsum ecosystem and current ClickFix campaign, using compromised WordPress sites, fake browser update lures, DLL sideloading, dead-drop C2 resolution, and post-exploitation tooling that can culminate in Rhysida ransomware deployment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.