vanhelsing

Malware type
ransomware
Family
Malware family
Last IoC activity
2026-04-25 21:11:06
Profile updated
2026-07-07 13:57:54

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical

Context

Designed to target Windows systems, this ransomware employs advanced encryption techniques and appends a unique file extension to compromised files. Its stealthy evasion tactics and persistence mechanisms make detection and removal challenging. This highlights the need for proactive cybersecurity measures and a robust incident response strategy to safeguard data integrity and minimize breach risks.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Vanhelsing_Auto (yara-rule)

Reports & references

  • ransomlook.io — Vanhelsing (report)
  • cyfirma.com — Vanhelsing Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Vanhelsing (report)
  • fortinet.com — Ransomware Roundup Vanhelsing (report)

External references