Vanilla Tempest

Aliases: DEV-0832, VICE SPIDER, Vice Society

First seen
2021-06-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:34:32

Targeted industries: education-and-nonprofits healthcare-and-pharmaceutical manufacturing

Context

Vice Society is a ransomware group that has been active since at least June 2021. They primarily target the education and healthcare sectors, but have also been observed targeting the manufacturing industry. The group has used multiple ransomware families and has been known to utilize PowerShell scripts for their attacks. There are similarities between Vice Society and the Rhysida ransomware group, suggesting a potential connection or rebranding.

Reports & references

  • Microsoft — Dev 0832 Vice Society Opportunistic Ransomware Campaigns Impacting Us Education Sector (report)
  • fourcore.io — Rhysida Ransomware History Ttp Adversary Emulation (report)
  • detect.fyi — Rhysida Ransomware And The Detection Opportunities 3599E9A02Bb2 (report)
  • research.checkpoint.com — The Rhysida Ransomware Activity Analysis And Ties To Vice Society (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references