Ransomware Group intelligence
VanHelsing
InactiveTrack VanHelsing with 9 published victims and 7 known leak locations in a single intelligence view.
Overview
VanHelsing is tracked by Breach House as a ransomware group with 9 published victims.
United States is currently the most targeted country in this dataset.
7 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (7)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 6 | Onion service | Down checked 1h ago | vanheltarnbfjhuvggbncniap56dscnzz5yf6yjmxqivqmb5r2gmllad.onion |
| Leak location 4 | Onion service | Down checked 1h ago | vanhelvuuo4k3xsiq626zkqvp6kobc2abry5wowxqysibmqs5yjh4uqd.onion |
| Leak location 7 | Onion service | Down checked 1h ago | vanhelcbxqt4tqie6fuevfng2bsdtxgc7xslo2yo7nitaacdfrlpxnqd.onion |
| Leak location 5 | Onion service | Down checked 1h ago | vanhelwmbf2bwzw7gmseg36qqm4ekc5uuhqbsew4eihzcahyq7sukzad.onion |
| Leak location 1 | Onion service | Down checked 1h ago | vanhelqmjstkvlhrjwzgjzpq422iku6wlggiz5y5r3rmfdeiaj3ljaid.onion |
| Leak location 3 | Onion service | Down checked 1h ago | vanhelxjo52qr2ixcmtjayqqrcodkuh36n7uq7q7xj23ggotyr3y72yd.onion |
| Leak location 2 | Onion service | Down checked 1h ago | vanhelsokskrlaacilyfmtuqqa5haikubsjaokw47f3pt3uoivh6cgad.onion |
Top Activity Sectors (5)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue VanHelsing, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: VanHelsing uses PowerShell scripts to execute malicious commands and deploy ransomware payloads across targeted systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: VanHelsing leverages registry run keys and startup folders to maintain persistence across reboots on compromised hosts.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: VanHelsing disables antivirus tools and security monitoring utilities to evade detection during initial compromise.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: VanHelsing injects junk code into legitimate binaries to evade static analysis and detection by security tools.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: VanHelsing deletes Volume Shadow Copies and backup directories to prevent victim recovery and increase ransom pressure.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: VanHelsing scans network shares to identify victim file structures and prepare for lateral movement or data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: VanHelsing uses SMB/Windows Admin Shares to move laterally between internal servers and file repositories.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1567.002 Exfiltration to Cloud Storage Exfiltration
What they do: VanHelsing exfiltrates sensitive victim data before encryption to enable extortion beyond ransomware demands.
What that means: Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: VanHelsing encrypts critical business files and documents using its ransomware payload to maximize operational disruption.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: VanHelsing calls system recovery inhibitors to block automatic restoration processes and sustain impact.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
README.txt
--= No news is a good news ! =-- Your network has been breached and all your files Personal data, financial reports and important documents has been stolen , encrypted and ready to publish to public, if you willing to continue your bussines and make more money and keep bussines secret safe you need to restore your files first, And to restore all your files you have to pay the ransom in Bitcoin. don't bother your self and wast your time or make it more harder on your bussines , we developed a locker that can't be decrypted using third part decrypters . making your self geek and trying to restore the files with third part decrypter this will leads to lose all your date ! and then the even you pay the ransom can't help you to restore your files even us. to chat with us : 1 - Download tor browser https://www.torproject.org/download/ 2 - go to one of these links above http://vanhelcbxqt4tqie6fuevfng2bsdtxgc7xslo2yo7nitaacdfrlpxnqd.onion http://vanhelqmjstkvlhrjwzgjzpq422iku6wlggiz5y5r3rmfdeiaj3ljaid.onion http://vanhelsokskrlaacilyfmtuqqa5haikubsjaokw47f3pt3uoivh6cgad.onion http://vanheltarnbfjhuvggbncniap56dscnzz5yf6yjmxqivqmb5r2gmllad.onion 3 - you will be asked for your ticket id to enter the chat this for you : TICKET ID [snip] usefull links : #OUR TOR BLOG : http://vanhelvuuo4k3xsiq626zkqvp6kobc2abry5wowxqysibmqs5yjh4uqd.onion http://vanhelwmbf2bwzw7gmseg36qqm4ekc5uuhqbsew4eihzcahyq7sukzad.onion http://vanhelxjo52qr2ixcmtjayqqrcodkuh36n7uq7q7xj23ggotyr3y72yd.onion
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (9)
Search, filter and paginate the victim timeline for VanHelsing. Showing 1–9 of 9.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | caschile.cl id18984 View details | Chile | IT | ||
|
CAS–CHILE® is a company with 30 years of experience in the Information Technology market, dedicated to the design, development, and maintenance of public and municipal management software. As experts in the design, construction, and maintenance of software for public management, we develop IT platforms distributed throughout the country with excellent results, backed by the improvement, optimiz |
|||||
| Ransomware | attorneykohm.com id18879 View details | United States | Finance / Legal / Insurance | ||
|
Attorney David KohmOffices throughout the Dallas Fort Worth AreaThe Law Offices of David Kohm have provided expert legal representation to the people of Arlington and Dallas Fort Worth for over 25 years. Our entire legal team is dedicated to one goal: Aggressively represent our clients to ensure the best possible outcome. We are not satisfied until you are made whole.When it comes to your financia |
|||||
| Ransomware | alertenterprise.com id18876 View details | United States | Communication / Marketing | ||
|
At the core of our mission is the seamless convergence of advanced physical access control, identity management, and workspace automation. Our solutions are designed to empower businesses with secure, flexible, and efficient work environments, catering to the dynamic needs of today’s workforce. We understand that in the digital era, the security of physical and digital assets is paramount. Our c |
|||||
| Ransomware | compumedics.com.au AND neuromedicalsupplies.com id18728 View details | Australia | IT | ||
|
A global leader in the development, manufacture and commercialisation of diagnostic technologies for the sleep, brain and ultrasonic blood-flow monitoring applications.Compumedics Limited (ASX: CMP) is a medical device company involved in the development, manufacture and commercialisation of diagnostics technology for the sleep, brain and ultrasonic blood-flow monitoring applications. The Company |
|||||
| Ransomware | studiocdlvallone.it id18661 View details | Italy | Communication / Marketing | ||
|
We put commitment, curiosity, passion, optimism into our work every day, with a single important goal: to be satisfied, to learn something new every day with the challenges that our profession offers us. We love teamwork and each of us is called upon to make our qualities and skills available to the group. Excellence, as well as the limits of each of us, are enhanced and absorbed by the group, so |
|||||
| Ransomware | www.medsrx.com id18523 View details | United States | Healthcare / Pharma | ||
|
In a world where technology makes everything easier, the old school pharmacy experience is still hard. Waiting in line is sucks, insurances don’t make sense, medications are expensive, and it’s impossible to ever speak to a pharmacist when needed. We started MEDS because the old pharmacy experience you’re used to needed to be changed, Yesterday! MEDS has been the go-to place to get hard to f |
|||||
| Ransomware | atos id18514 View details | France | Communication / Marketing | ||
|
assemblies.atos appears to be an Atos-related entity in France, within a broader group known for digital transformation, secure IT services, and communications-oriented enterprise solutions. Atos is headquartered in Bezons, near Paris, and its services brand delivers AI-powered, secure, end-to-end digital services to public and private organizations worldwide. Public profiles describe the group as active in cloud, cybersecurity, big data, and unified communications, with global operations and consulting capabilities. In threat-intelligence catalogs, assemblies.atos was listed as a ransomware victim associated with VanHelsing. |
|||||
| Ransomware | Atos-racks.com id18507 View details | France | Communication / Marketing | ||
|
ATOS designs, develops and manufactures in France enclosure products for the electronics industry: cabinets, boxes, racks, fine and precision sheet metal assemblies, 19" indoor or outdoor solutions: standard, adaptation of the standard, specific, or production to drawings, up to the integration of complex assemblies.ATOS serves the Energy, Telecommunications, Electronics, IT and Transport markets, |
|||||
| Ransomware | www.cityofbellville.com id18466 View details | United States | Public Sector | ||
|
Bellville is a city in and the county seat of Austin County, Texas, in the southeastern part of the state. The population was 3,794 at the 2000 census. Bellville was named for Thomas B. Bell, one of Stephen F. Austin's Old Three Hundred, after he donated land for the new county seat established by voters in 1846. The original county seat was located in San Felipe. Bellville is located at the inter |
|||||