Vatet is a custom Windows malware loader associated with a financially motivated intrusion cluster linked to PyXie and Defray777/RansomExx operations. Active since at least 2018, the group has targeted organizations in healthcare, education, government, and technology, with repeated reporting highlighting a particular focus on healthcare and other critical sectors. Vatet commonly functions as an early-stage execution component in human-operated intrusions, loading follow-on payloads such as Cobalt Strike and updated PyXie variants, and has been observed as a precursor to enterprise ransomware deployment.
The loader is notable for abusing modified open-source applications as trojanized carriers, including variants built from Rainmeter, Notepad, Notepad++, and a Tetris game. In these forms, the visible application remains largely legitimate while added malicious code reads an encrypted or XOR-encoded payload from local disk or a network share, decodes it, and executes it directly in memory. Some variants improve anti-forensics by deleting the payload file after loading. Vatet has also been observed in trojanized software used in suspected watering-hole activity, and later propagation inside victim environments via administrative shares has been reported.
Vatet supports in-memory execution of shellcode and backdoor payloads and has been used to deliver Cobalt Strike Beacon as well as PyXie components. Earlier variants loaded payloads from UNC paths, while later variants more often used local masqueraded data files placed under Windows directories. Reporting also links Vatet to campaigns in which initial access was obtained through phishing, commodity malware such as IcedID or Trickbot, brute-forced remote access, exploitation of internet-facing systems including Citrix ADC CVE-2019-19781, and malicious shortcut-based email lures that launched PowerShell.
Operationally, Vatet sits within a broader intrusion chain in which the actors establish access, deploy Vatet to launch post-exploitation tooling, conduct reconnaissance and theft with PyXie or PyXie Lite, and in some cases culminate with in-memory deployment of Defray777 ransomware. Shared development artifacts and code similarities have been reported across Vatet, PyXie, and Defray777, supporting assessment that they are maintained by the same threat group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We first noticed that there may be a relationship between the Vatet loader, PyXie Remote Access Tool (RAT) and Defray777 ransomware... During our research, we discovered that this threat group has developed and maintained the Vatet loader.
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware, Vatet loader, and Defray ransomware strains.
We first noticed that there may be a relationship between the Vatet loader, PyXie Remote Access Tool (RAT) and Defray777 ransomware... During our research, we discovered that this threat group has developed and maintained the Vatet loader.
RansomExx is operated by the DefrayX threat actor group (Hive0091), which is also known for the PyXie malware, Vatet loader, and Defray ransomware strains.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
the sample performed a first-level decoding of the contents by XOR-ing the contents with the value FE... there is a second decoding routine where an additional dynamic XOR loop is used to decode and rewrite the contents of the executable code.
CTIR identified the likely infection vector as an IcedID phishing email with a ZIP attachment that used steganography for loading commands to the Vatet loader itself.
If it is determined to be running as LocalSystem, the payload is injected into a newly spawned process chosen from the Windows directory. If not found to be running as LocalSystem, the payload will execute in the memory space of the current process.
98 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader associated with the DefrayX group, mentioned as part of the group's malware arsenal.
Ransomware variant highlighted as a top-observed threat this quarter, with noted targeting of healthcare organizations.
Loader/ransomware used in attacks against healthcare organizations; in the described intrusion it was delivered by IcedID and led to Cobalt Strike activity and eventual Defray777 deployment.
A trojanized Notepad++-based loader/backdoor family detected as VATET that loads encrypted blob files (config.dat), decrypts payloads in memory, and executes backdoor routines. The same loader was observed delivering different secondary payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.