Vanir Group Active
Nordic-themed emerging operation0
Total Victims
2025-01-01
First Seen
N/A
Last Seen
15
Known TTPs
10.9d
Avg Delay
0
Negotiations
ONION URLS
6xdpj3sb5kekvq5ulym5qqmzsv6ektjgvpmajns3qrafgxtyxrhokfqd.onion
TOOLS
Rust+Go hybrid
FILE EXTENSIONS
.vanir
ACTIVITY TIMELINE
TOP SECTORS
TOP COUNTRIES
ACTIVITY HEATMAP
| Date | Victim Name | Country | Sector | Status |
|---|---|---|---|---|
| No victims recorded | ||||
| Technique ID | Technique Name | Tactic |
|---|---|---|
| T1105 | Ingress Tool Transfer | Command and Control |
| T1003.003 | NTDS | Credential Access |
| T1110.001 | Password Guessing | Credential Access |
| T1552.001 | Credentials In Files | Credential Access |
| T1036.005 | Match Legitimate Name or Location | Defense Evasion |
| T1055 | Process Injection | Defense Evasion |
| T1140 | Deobfuscate/Decode Files | Defense Evasion |
| T1049 | System Network Connections Discovery | Discovery |
| T1135 | Network Share Discovery | Discovery |
| T1053.005 | Scheduled Task | Execution |
| T1567.002 | Exfiltration to Cloud Storage | Exfiltration |
| T1078 | Valid Accounts | Initial Access |
| T1566.002 | Spearphishing Link | Initial Access |
| T1543.003 | Windows Service | Persistence |
| T1547.009 | Shortcut Modification | Persistence |
No YARA rules
No IoCs
No ransom notes