Ransomware Group intelligence
Vicesociety
InactiveTrack Vicesociety with 191 published victims and 9 known leak locations in a single intelligence view.
Overview
Vicesociety is tracked by Breach House as a ransomware group with 191 published victims.
United States is currently the most targeted country in this dataset.
9 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (9)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 9 | Onion service | Down checked 2h ago | bianlianlbc5an4kgnay3opdemgcryg2kpfcbgczopmm3dnbz3uaunad.onion |
| Leak location 8 | Onion service | Down checked 2h ago | xu66gzit6zp22qvixpenlxu2ok7vzrpqvgkuupkiukpz47va47ewbwad.onion |
| Leak location 7 | Onion service | Down checked 2h ago | tahnytazh47jpikpajm2so2jdsjrkx6gfcu4p7bu7u3vfarnpvshgeyd.onion |
| Leak location 6 | Onion service | Down checked 2h ago | ml3mjpuhnmse4kjij7ggupenw34755y4uj7t742qf7jg5impt5ulhkid.onion |
| Leak location 5 | Onion service | Down checked 2h ago | ssq4zimieeanazkzc5ld4v5hdibi2nzwzdibfh5n5w4pw5mcik76lzyd.onion |
| Leak location 4 | Onion service | Down checked 2h ago | wmp2rvrkecyx72i3x7ejhyd3yr6fn5uqo7wfus7cz7qnwr6uzhcbrwad.onion |
| Leak location 2 | Onion service | Down checked 2h ago | vsociethok6sbprvevl4dlwbqrzyhxcxaqpvcqt5belwvsuxaxsutyad.onion |
| Leak location 3 | Onion service | Down checked 2h ago | ecdmr42a34qovoph557zotkfvth4fsz56twvwgiylstjup4r5bpc4oad.onion |
| Leak location 1 | Onion service | Down checked 2h ago | 4hzyuotli6maqa4u.onion |
Top Activity Sectors (17)
- Not identified 56
- Education 52
- Communication / Marketing 12
- Public Sector 12
- Services 11
- Healthcare / Pharma 11
- Finance / Legal / Insurance 6
- Retail / E-commerce 5
- IT 5
- Manufacturing / Engineering 4
- Construction / Real Estate 3
- Telecommunications 3
- Agriculture / Food 2
- Hospitality / Food & Beverage / Tourism 2
- NGOs / Associations 2
- Energy 1
- Transportation / Travel / Logistics 1
Typical Attacks (9)
▼MITRE ATT&CK does not currently catalogue Vicesociety, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: vicesociety executes malicious payloads using PowerShell scripts to stage ransomware deployment across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: vicesociety persists by injecting malicious registry run keys to ensure ransomware reactivation after system reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: vicesociety disables antivirus tools and security monitoring solutions using registry modifications and service termination commands.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: vicesociety deletes Volume Shadow Copies and backup directories via vssadmin commands to prevent data recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: vicesociety discovers remote systems via Remote System Discovery to map the victim network for targeted encryption.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: vicesociety scans network shares to identify victim directories and victim data for exfiltration or encryption targets.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: vicesociety moves laterally through SMB/Windows Admin Shares to propagate ransomware binaries across networked hosts.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: vicesociety encrypts victim files using custom ransomware binaries with cryptographic keys derived from victim system data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: vicesociety displays internal defacement messages and ransom notes on victim workstations to pressure decryption payments.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Tools Observed (15)
▼Software Vicesociety has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Discovery & enumeration
Exfiltration
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
vicesociety.txt
ALL YOUR FILES HAVE BEEN ENCRYPTED BY VICE SOCIETY All your important documents, photos, databases were stolen and encrypted. If you do not contact us in 7 days we will upload your files to darknet! The only method of recovering files is to purchase an unique private key. We are the only who can give you tool to recover your files. To proove that we have the key and it works you can send us 2 files and we decrypt it for free (not more than 2 MB each). This file should be not valuable! Write to email: CoryFrempton@onionmail\.org Alternative email: DanyTron@onionmail\.org v-society.official@onionmail\.org Attention! Do not rename encrypted files. Do not try to decrypt your data using third party software, it may cause permanent data loss. Decryption of your files with the help of third parties may cause increased price (they add their fee to ours) or you can become a victim of a scam. Visit our website 4hzyuotli6maqa4u\.onion Use tor browser to open
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (191)
Search, filter and paginate the victim timeline for Vicesociety. Showing 101–191 of 191.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Consejo Superior de id3969 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Vygon Spain id3957 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CHDE POLSKA id3843 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Edenfield id3838 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | XQUADRAT GmbH id3827 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | San Luis Coastal Unified id3826 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Vectalia group id3734 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ministry of Agriculture Rebublic Indonesia id3691 View details | Indonesia | Agriculture / Food | — | |
|
Indonesia's rich natural resources are influenced by its tropical climate and geographical location between two continents, Asia and Australia, and two oceans, the Pacific Ocean and the Indian Ocean. Therefore, Indonesia is known as an agrarian country with a variety of products from agriculture, plantations, livestock, fisheries and forestry. |
|||||
| Ransomware | Medical University of Innsbruck id3688 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | PT Astra Honda Motor id3678 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pilton Community College id3677 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ospedale Macedonio Melloni id3669 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Novelty Group id3646 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Magnum id3642 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Grand Valley State University id3627 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Palermo id3612 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | St Paul id3582 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Acorn Recruitment id3581 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The De Montfort School id3580 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Catholic Foundation id3485 View details | NGOs / Associations | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Atlanta Perinatal Associates id3471 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Carmel College id3470 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Higher School of the Public id3469 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Trans Technology Pte Ltd. id3413 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Caldes de Montbui id3412 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Salud Total id3411 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ELTA Hellenic Post id3370 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Haynes Manuals id3369 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Asia Pacific University id3361 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mercadocar Mercantil Ltda. id3319 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Suhl. City in Germany id3318 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Associazione Bancaria Italiana id3315 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Domingues and Pinho Contadores id3314 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Building Plastics, Inc. id3313 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Fonseca Supermarkets id3312 View details | Retail / E-commerce | — | ||
|
No additional victim description available. |
|||||
| Ransomware | GOLDENDUCK GROUP id3311 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Levantina, Ingenieria y Construccion id3303 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Stratton Finance id3302 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Est Ensemble id3301 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CORFERIAS id3296 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ALMANIE GROUP id3295 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Mossbourne Federation id3254 View details | NGOs / Associations | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Centre Hospitalier de Castelluccio id3253 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Small Industries DevelopmentBank of India id3239 View details | India | Finance / Legal / Insurance | — | |
|
Small Industries Development Bank of India is the apex regulatory body for overall licensing and regulation of micro, small and medium enterprise finance companies in India. It is under the jurisdiction of Ministry of Finance, Government of India headquartered at Lucknow and having its offices all over the country. |
|||||
| Ransomware | Maristes Hermitage id3235 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | NuLife Med id3191 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | APSM Systems id3002 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ASPIRO id2997 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ciments Guyanais id2996 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | OSSEG Obra Social del Seguro id2991 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Jammal Trust Bank id2986 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Establishment of the Agency for the Environmental Protection of the Marche Region id2954 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ICEHOTEL id2936 View details | Hospitality / Food & Beverage / Tourism | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Griggsville-Perry High School id2935 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SENADO Argentina id2821 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Optionis id2526 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Butler County Community College id2440 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Durham Cathedral Schools Foundation id2432 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Butler Community College id2431 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | XAL id2430 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SAVANNAH State University id2414 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Carthage R-9 School District id2413 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Amaveca Salud id2406 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rolle id2398 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Alliance COAL, LLC id2397 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Whitehouse id2396 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | FILGO id2395 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Walter's Automotive Group id2394 View details | Manufacturing / Engineering | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Gateway College id2393 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Centre Hospitalier D'Arles id2392 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | 3V Sigma id2391 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Eskenazi Health Foundation id2390 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Butali id2389 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Plastipak Holdings, Inc. id2388 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Barlow Respiratory Hospital id2387 View details | Healthcare / Pharma | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ROC Mondriaan id2386 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | KESSEL AG id2385 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Karl Bachl GmbH & Co.KG id2384 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | SRH Holding id2383 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Manhasset Union Free School District id2382 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Lufkin Independent School District id2381 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | City of Witten id2380 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Holy Family RC & CE College id2379 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Hawthorn The Community Pub Co. id2378 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pontificia Universidad Javeriana id2377 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | DFL id2376 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Spar id2375 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | OSSEG Obra Social de Seguros id2341 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Universidade Federal de Sao Paulo id2340 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | United Health Centers id684 View details | United States | Healthcare / Pharma | — | |
|
No additional victim description available. |
|||||
| Ransomware | City of Rolle id642 View details | Switzerland | Public Sector | — | |
|
No additional victim description available. |
|||||