Vice Society is a ransomware and data-extortion operation first identified in June 2021. The name is used for both the criminal operation and ransomware deployed under its branding. It conducts human-operated, double-extortion attacks, stealing organizational data before encrypting systems and threatening to publish the stolen information unless a ransom is paid. Its victims include education, healthcare, manufacturing, government, and logistics organizations across multiple countries, with a particularly prominent concentration in education and healthcare.
Vice Society initially deployed third-party ransomware, including HelloKitty/FiveHands and Zeppelin, before adopting custom ransomware. A custom variant named PolyVice emerged in December 2022. Vice Society-associated encryptors have targeted Windows and Linux systems, and attacks have affected Windows virtual-server environments, including Microsoft Hyper-V.
Observed intrusions used valid VPN credentials on accounts without multifactor authentication, followed by network discovery, credential dumping, and lateral movement through RDP and other remote-administration mechanisms. Vice Society has also exploited PrintNightmare vulnerabilities, including CVE-2021-1675 and CVE-2021-34527. Attack tooling has included Cobalt Strike, Mimikatz, Rubeus, PortStarter, and SystemBC. Attackers have established persistent access, disabled security protections, terminated application and security processes, deleted shadow copies, and cleared event logs. Data theft has used transfer utilities and custom PowerShell exfiltration scripts.
The operation is associated with the financially motivated actor tracked as GOLD VICTOR, with overlapping activity tracked as Vanilla Tempest and TAC5279. An affiliate cluster observed deploying Vice Society ransomware subsequently switched to Rhysida in June 2023 while retaining consistent tooling and tradecraft; this transition does not establish that the ransomware families are identical.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Группа вымогателей Vice Society теперь активно использует уязвимость PrintNightmare (CVE-2021-1675 и CVE-2021-34527) диспетчера очереди печати Windows для бокового перемещения по сетям своих жертв. | Название: Vice Society. Вероятно спин-офф от HelloKitty ... Группа вымогателей Vice Society теперь активно использует уязвимость PrintNightmare (CVE-2021-1675 и CVE-2021-34527).
The situation began in June with CVE-2021-1675 ... There was confusion when researchers published a proof-of-concept (PoC) called “PrintNightmare,” stating it was for CVE-2021-1675 when it was actually a distinct vulnerability.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This group has been linked to the Vice Society and Rhysida ransomware families.
This group has been linked to the Vice Society and Rhysida ransomware families.
This group has been linked to the Vice Society and Rhysida ransomware families.
"...we identified a ransomware affiliate group move from deploying Vice Society to leveraging Rhysida ransomware in attacks against enterprises."
6 distinct techniques documented for this family, organized by ATT&CK tactic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family mentioned as background to the attribution of Lorem Ipsum Loader to Rapid Brigantine, also tracked as GOLD VICTOR. The content does not report its deployment in STAC4924; Sophos observed no encryption in that campaign.
Previously disrupted ransomware operation with an assessed, but unconfirmed, tactical or personnel-overlap connection to Rhysida.
A ransomware group known for targeting organizations with human-operated campaigns, exploiting vulnerabilities in unsupported or unpatched Windows systems.
Ransomware strain used in extortion operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.