vanhelsing
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-04-25 21:11:06
- Profile updated
- 2026-07-07 13:57:54
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical
Context
Designed to target Windows systems, this ransomware employs advanced encryption techniques and appends a unique file extension to compromised files. Its stealthy evasion tactics and persistence mechanisms make detection and removal challenging. This highlights the need for proactive cybersecurity measures and a robust incident response strategy to safeguard data integrity and minimize breach risks.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Vanhelsing_Auto (yara-rule)
Reports & references
- ransomlook.io — Vanhelsing (report)
- cyfirma.com — Vanhelsing Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Vanhelsing (report)
- fortinet.com — Ransomware Roundup Vanhelsing (report)