Informa TechTarget | Cybersecurity Dive InformationWeek Channel Dive TechTarget: Cybersecurity Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Cyberattacks & Data Breaches Maximum Severity GitLab Flaw Puts Supply Chains at Risk Maximum Severity GitLab Flaw Puts Supply Chains at Risk by Rob Wright Sep 14, 2026 3 Min Read Sponsored Content The Mythos Panic Is Over. The Budget Window Isn't. The Mythos Panic Is Over. The Budget Window Isn't. Sep 14, 2026 5 Min Read World Related Topics DR Global Asia Pacific Europe Latin America Middle East & Africa See All The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Endpoint Security Cyber Risk Threat Intelligence Vulnerabilities & Threats News VectraRAT Can Hack Windows Enterprises for $250 per Month The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. Elizabeth Montalbano , Contributing Writer September 15, 2026 5 Min Read Source: David Chapman via Alamy Stock Photo An original, full-stack malware-as-a-service (MaaS) platform gives cyberattackers all they need to compromise an organization's enterprise networks, demonstrating how it's becoming less expensive to develop a cybercriminal business with custom malware than it is to pay off a mortgage. Researchers from SOCRadar discovered VectraRAT, a previously undocumented platform that includes a full-featured Windows implant, command-and-control (C2) infrastructure, and an operator panel built entirely from scratch rather than based on existing malware, according to a new report published. This sets it apart from other MaaS platforms designed for initial access into an organization's network, which typically leverage and build upon other malware, according to the report. "Most remote access tools sold on crimeware forums are borrowed goods. A leaked AsyncRAT build, a cracked XWorm license, a QuasarRAT fork with a new icon and a new name," according to SOCRadar's report. Related: SpiderSilk Hunts External Threats With AI-Based Scanner VectraRAT is a different case, however, in which "every layer of it, the Linux control server, the Windows implant, the protocol between them, the licensing that keeps operators paying, was written by the same developer," according to the report. "None of it had been publicly documented." And using it costs customers only $250 per month. "What really raises the bar here is how full-featured this solution is and how it’s built completely from scratch rather than being a fork from another MaaS solution," Denis Calderone, chief technology officer of security firm Suzu Labs, tells Dark Reading. "It's very sophisticated, does user account control (UAC) bypass, it uses proprietary protocols for C2, and is priced like any midtier software-as-a-service (SaaS) application." A Snapshot of the VectraRAT Malware The operator behind VectraRAT has been active for nearly four years without detection; the researchers found an older identity, "Nyxel," with a YouTube channel dating back to August 2022. However, the rebrand appears to be merely "marketing deep" — the researchers observed the operator presenting "the old Nyxel Hub and the new VectraHub side by side, with no functional difference between them," according to the report. SOCRadar didn't discover the platform until June 23, when its researchers observed an open directory that led them to investigate across more than 10 servers, dozens of samples, panel logs belonging to real operators, and a Telegram conversation with the platform's developer. During that conversation, the developer offered add-on services, such as fully detectable crypting services, for between $100 and $350 per month, as well as a bundled package with the crypting and other services quoted above $2,000. The developer also demonstrated scan results against named antivirus (AV) products, "while noting that detection varies by product, version, and configuration," according to the researchers. Related: ClickFix Campaigns Abuse Legitimate Services for Persistent Access A typical version of VectraRAT provides capabilities associated with any mature remote-access implant, according to SOCRadar. The malware is delivered through Amadey loader and ClickFix pages, the latter of which is a popular social engineering vector for attackers. Once installed, it can provide attackers with a hidden desktop, remote CMD and PowerShell access, keylogging, file transfer, process discovery, clipboard manipulation, and SOCKS5 proxy functionality. The platform also automatically collects browser credentials and searches for potentially valuable .env, .conf, and .config files when a victim first connects to the attacker's infrastructure, according to the report. This gives an attacker access to sensitive data, but it also adds persistent interactive access to a compromised machine, giving them a foothold from which to conduct other malicious activities . These might include poking around inside the environment, stealing additional credentials, accessing sensitive files, and potentially moving deeper into the organization, according to SOCRadar. Related: ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain User Account Control Bypass Sets the RAT Apart VectraRAT also incorporates a UAC-bypass technique that can obtain a high-integrity process without showing the victim the usual elevation prompt. "This is the part of VectraRAT that separates it from the $50 tier," according to the report. This feature allows an attacker to turn an initially compromised user workstation into a more powerful platform for subsequent activity. SOCRadar did not find any specific geographic or sector targeting in its investigation of VectraRAT, but it noted that the US, Russia, and Germany were the regions most represented in the victim data. Moreover, operators selected high-value hosts for hands-on exfiltration afterward, with 48% of victim entries corresponding to corporate Windows editions, including Windows Enterprise , Enterprise LTSC, IoT Enterprise LTSC, and Windows Server 2025. Furthermore, the researchers confirmed file exfiltration from the compromised systems. "It's pretty obvious that this is being sold as a solution for attacking higher-value corporate targets," Calderone says. What VectraRAT Means for Cyber Defenders For defenders, the appearance of VectraRAT goes beyond just giving them another RAT to detect with security measures. It also shows how the cybercrime economy is continuing to move toward subscription-based, professionally developed attack infrastructure that consistently lowers the technical barrier for criminals while giving defenders another sophisticated threat to contend with, the researchers noted. "In the before times, this would have taken a year-plus to develop and probably would have been buggy," Calderone says. "It used to not be worth the effort, but now you can just vibe code these things into existence . I would expect more of things like this, not less." Fortunately for typical defense measures, VectraRAT leaves a trackable trail, and SOCRadar provided organizations with indicators of compromise (IoCs) and other clues to look out for. These include specific IoCs that come in the form of a C2 override file; Outbound TCP 3308: auto-elevation abuse; a debug API sequence; and a hidden PowerShell, among others included in the report. From a human observer perspective, the researchers also gave defense notes for defending against ClickFix as an initial entry vector, noting that "a verification page that asks someone to open the Run dialog and paste a command is never legitimate," and advising that they used a single rule to close the delivery path used "in the most active campaign we documented," according to the report. About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. See more from Elizabeth Montalbano Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Cybersecurity Outlook 2027 Threat Exposure Analytics: Measuring and Communicating Security R