Home/Threat Actor/Vice Society / Vanilla Tempest
Threat Actor

Vice Society / Vanilla Tempest

vice_society_vanilla_tempest · russia_speaking_organized_cybercrime · active since 2021-06

Vice Society / Vanilla Tempest (Microsoft DEV-0832 - Vanilla Tempest.

Sophos TAC5279.

CrowdStrike VICE SPIDER) is a Russia-speaking financially-motivated organized cyber- criminal ransomware cluster active since June 2021 with a disproportionate education-sector and healthcare-sector targeting profile, an operationally-distinctive multi- ransomware-payload deployment pattern (Hello Kitty/Five Hands, Zeppelin, BlackCat, Quantum Locker, custom Vice Society- branded encryptor, Rhysida from June 2023, INC ransomware from September 2024), signature operator-tradecraft including PortStarter+SystemBC C2, NTDSUtil-to-temp_l0gs Active- Directory-dump path, AnyDesk remote access, and MegaSync exfiltration, and a high-confidence mid-2023 operator-membership pivot from Vice Society brand to Rhysida brand (canonical Sophos X-Ops / Check Point Research / PRODAFT independent- converging attribution)

compromised LAUSD (September 2022), Chilean Army (May 2023), Prospect Medical Holdings 17 US hospitals + 166 clinics (August 2023), and many education- and-healthcare-sector organizations across the US, UK, Canada, Australia, and broader Western jurisdictions.

prompted CISA/FBI/ MS-ISAC AA22-249A joint advisory (September 2022) and ongoing US HHS HC3 healthcare-sector alerts.

russia_speaking_organized_cybercrime confidence: high 17 aliases

Profile

Vice Society / Vanilla Tempest (also tracked as Microsoft DEV-0832 [legacy] and Vanilla Tempest [current], Sophos TAC5279, CrowdStrike VICE SPIDER) is a Russia-speaking financially-motivated organized cyber-criminal ransomware cluster active publicly from June 2021 through the present (continuing under updated branding through Rhysida operational era June 2023 onward and INC ransomware deployment from September 2024 onward). The cluster is operationally significant for two distinguishing characteristics versus the broader Russia-speaking-organized-cybercrime ransomware ecosystem: (1) DISPROPORTIONATE EDUCATION-SECTOR TARGETING. From late 2021 through 2022, Vice Society developed and sustained an operational pattern of disproportionate targeting against education-sector organizations, K-12 school districts, higher-education universities, and state-and-local education- system organizations across the United States, United Kingdom, Canada, Australia, and broader English-speaking jurisdictions.

The education-sector targeting pattern attracted substantial US government attention culminating in the September 6, 2022 CISA/FBI/MS-ISAC joint cybersecurity advisory AA22-249A explicitly warning US education-sector organizations of elevated Vice Society targeting in the pre-back-to-school operational period. The most operationally-visible Vice Society operation was the September 2022 compromise of the Los Angeles Unified School District (LAUSD, the second- largest US K-12 school district serving approximately 600,000 students), during which the cluster published approximately 500 GB of stolen LAUSD data after the district publicly refused to pay ransom, an operational escalation that drew additional US-government and partner-government attention. (2) MULTI-RANSOMWARE-PAYLOAD OPERATIONAL PATTERN.

The cluster's operational pattern of deploying multiple distinct ransomware- payload families across its operational history is operationally distinctive versus typical ransomware-as-a- service affiliate clusters that operate under a single RaaS brand. Vice Society / Vanilla Tempest has operationally deployed Hello Kitty / Five Hands, Zeppelin (variants with Vice Society file extensions .v-s0ciety, .v-society, and .locked), BlackCat / ALPHV, Quantum Locker, Vice Society's own branded ransomware payloads, Rhysida (from June 2023 onward as primary payload), and most recently INC ransomware (from September 2024 onward against US healthcare-sector organizations). The cluster operates a centralized operator- team model rather than affiliate-based RaaS model, with the same underlying operator membership deploying changing ransomware-payload families operationally consistent with operator-team-decision-making rather than affiliate-level RaaS-brand-selection.

Signature operational tradecraft includes
  • Initial access via valid VPN credentials against VPN-deployments-without-MFA-enforcement (one of the strongest consistent initial-access vectors across the cluster's operational history; defensive mitigation specifically called out in CISA AA22-249A);.
  • Exploitation of PrintNightmare (CVE-2021-34527) for privilege escalation when initial valid-credential access does not provide sufficient privileges (signature Vice Society exploitation pattern);.
  • Heavy use of PowerShell, custom svchost.ps1 SystemBC persistence script at HKCU\Software\Microsoft\Windows\ CurrentVersion\Run\socks registry value (signature persistence artifact);.
  • PortStarter backdoor for command-and-control (signature tooling, almost exclusively associated with Vice Society operators in public reports);.
  • SystemBC SOCKS5 proxy for command-and-control (signature C2 tooling, primary C2 method after PortStarter discontinuation following Rhysida pivot);.
  • NTDSUtil to dump NTDS.dit Active Directory credentials to a folder named temp_l0gs (signature filepath operational artifact, consistent across both Vice Society and Rhysida operational eras);.
  • Advanced Port Scanner / Advanced IP Scanner for network reconnaissance (signature reconnaissance tool);.
  • AnyDesk as the primary remote-access dual-use tool (signature operational preference vs. TeamViewer, Splashtop, ConnectWise that are observed less frequently);.
  • MegaSync (Mega.nz cloud-storage client) for data exfiltration (signature exfiltration tool);.
  • 7zip for staged data archival prior to exfiltration (signature archiving tool);.
  • PsExec for ransomware-payload distribution to compromised hosts during deployment phase, with the recent INC ransomware operations transitioning to Windows Management Instrumentation (WMI) Provider Host for ransomware distribution;.
  • Selective non-deployment of ransomware in some intrusions: Microsoft MSTIC October 2022 disclosure noted that some Vice Society intrusions did not deploy ransomware (data- exfiltration-only extortion model). The selective-no-encryption operational option is operationally available to the cluster but is not the dominant operational pattern. The operator-membership pivot from Vice Society brand to Rhysida brand in mid-2023 represents one of the highest- confidence ransomware-operator-rebrand attributions in modern cyber-threat-intelligence reporting. The Sophos X-Ops November 2023 disclosure (TAC5279), Check Point Research / CPIRT August 2023 disclosure, and PRODAFT analysis independently converged on the high-confidence assessment that Vice Society operators pivoted to deploying Rhysida ransomware in the June-July 2023 timeframe based on: (a) shared PortStarter backdoor tooling (almost exclusively associated with Vice Society in public reports prior to the pivot); (b) shared NTDSUtil-to-temp_l0gs operational artifact path; (c) shared SystemBC C2 deployment pattern; (d) Vice Society data-leak- site cessation in July 2023 coinciding with Rhysida data- leak-site activation in approximately the same timeframe; (e) consistency of target sectors (education + healthcare) across both branded operational eras. Rhysida ransomware is curated separately in this corpus as rhysida_ransomware.yaml; this YAML (Vice Society / Vanilla Tempest) represents the underlying operator cluster across both Vice Society-branded (2021-July 2023), Rhysida-branded (June 2023-onward), and INC-ransomware-deployment-era (September 2024 onward) operational phases. The October 2025 Microsoft revocation of approximately 200 fraudulent code-signing certificates that the cluster had been using to sign Oyster backdoor variants in malvertising campaigns impersonating Microsoft Teams installers represents the operationally-most-recent vendor-level disruption action against the cluster's tooling, demonstrating that the cluster continues to operate productively under its current Vanilla Tempest tracking label as of the curation date with continuing operational evolution and operational continuity. The cluster is one of the most operationally-significant longitudinal examples of organized-cybercrime ransomware-operator branding and rebranding patterns in modern cyber-threat-intelligence history.

Aliases

17
vice societyvice_societyvicesocietydev-0832dev0832vanilla tempestvanillatempesttac5279tac-5279vice spidervicespiderdev-1222vsocietyvice society ransomwarevanilla tempest (vice society)vice_society_vanilla_tempestvice_society / vanilla_tempest

Notable Campaigns

9
2025Microsoft Revocation of Vanilla Tempest Code-Signing Certificates (October 2025)
2024INC Ransomware Deployment Against US Healthcare Sector (September 2024 onward)
2023Operator Pivot from Vice Society to Rhysida Brand (June - July 2023)
2023Rhysida-Era High-Profile Victims: Chilean Army + Prospect Medical Holdings (May - August 2023)
2022Los Angeles Unified School District Compromise (September 2022)
2022CISA + FBI + MS-ISAC AA22-249A Joint Advisory on Vice Society (September 6, 2022)
2022Microsoft MSTIC: DEV-0832 (Vice Society) Education-Sector Campaign Tracking (October 25, 2022)
2021-2022Disproportionate Education-Sector Targeting Pattern (2021-2022)
2021Vice Society Operational Emergence (June 2021)

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence CenterCISAFBIMS-ISAC (Multi-State Information Sharing and Analysis Center)Sophos X-OpsCheck Point Research (CPR + CPIRT)PRODAFTTrellixHuntressCrowdStrikeMandiantCybereasonRecorded FutureSentinelOnePalo Alto Networks Unit 42Trend MicroIntrinsecMalpedia
Key reporting
reportCISA + FBI + MS-ISAC AA22-249A: #StopRansomware, Vice Society (September 6, 2022; updates through 2023), canonical US-government formal-attribution
reportMicrosoft Threat Intelligence Center: DEV-0832 (Vice Society) Opportunistic Ransomware Campaigns Impacting US Education Sector (October 25, 2022), canonical industry vendor profile
reportSophos X-Ops: Same Threats, Different Ransomware, TAC5279 (November 10, 2023), canonical Vice Society to Rhysida operator-pivot attribution
reportCheck Point Research + CPIRT: The Rhysida Ransomware, Activity Analysis and Ties to Vice Society (August 2023)
reportPRODAFT: Rhysida Ransomware Operational Profile (2023)
reportIntrinsec: Vice Society Operational Analysis (June 2023)
reportMicrosoft Threat Intelligence: Vanilla Tempest INC Ransomware Healthcare Sector Tracking (September 2024)
reportMicrosoft Threat Intelligence: Vanilla Tempest Oyster Backdoor + Microsoft Teams Installer Malvertising (October 2025)
reportUS HHS HC3 Health Sector Cybersecurity Coordination Center: Rhysida Ransomware Sector Alert (August 2023)
reportHuntress Labs: Vice Society Threat Actor Profile
reportTrellix Advanced Research Center: Vice Society Tracking
reportCrowdStrike: VICE SPIDER Education-Sector Targeting
reportCybereason: Threat Analysis Report, Vice Society Versus PrintNightmare
reportRecorded Future Insikt Group: Vice Society Operational Analysis (multiple years)
reportMandiant: Vice Society to Rhysida Operator Tracking
reportMalpedia Actor Profile: Vanilla Tempest

Operational

State sponsor

Russia-speaking organized cyber-criminal cluster, financially- motivated. Industry vendor analysis (Microsoft MSTIC, Sophos X-Ops, Check Point Research, Huntress, Trellix) consistently tracks the cluster as Russia-speaking based on operational indicators including operator-language artifacts, victimology avoidance of CIS-region targets, infrastructure-provider patterns, ransom-negotiation behavioral patterns, and tradecraft patterns consistent with the broader Russia-speaking-organized- cybercrime ransomware ecosystem. No state-actor attribution has been formally asserted by any government cybersecurity authority. The cluster operationally pivoted in mid-2023 from using Vice Society-branded ransomware (Vice Society became operationally inactive on its data-leak site after July 2023) to deploying Rhysida ransomware under what Check Point Research and Sophos X-Ops independently attribute as the same underlying operator membership (with high confidence based on shared PortStarter C2 tooling, shared NTDSUtil-to-temp_l0gs operational pattern, and shared SystemBC C2 deployment). The Vice Society operators have also been observed deploying BlackCat / ALPHV, Quantum Locker, Zeppelin, Hello Kitty / Five Hands, and (per Microsoft September 2024 MSTIC tracking) INC ransomware under the same operator membership umbrella. The cluster's deployment- of-multiple-ransomware-payloads operational pattern is one of the most operationally distinctive features versus typical ransomware-as-a-service affiliate clusters that operate under a single RaaS brand. Rhysida is curated separately in this corpus as rhysida_ransomware.yaml.

this YAML represents the underlying Vice Society / Vanilla Tempest operator cluster that deployed Vice Society-branded ransomware 2021-July 2023 and operationally migrated to Rhysida and subsequently INC ransomware from mid-2023 onward.

Motivations
financial_ransom, double_extortion_data_theft_and_encryption, opportunistic_ransomware_against_under_resourced_sectors
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEGASYNCSECRETSDUMPSHARPHOUNDSPLASHTOPSUPPER MALWARE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin