SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt.
Key Takeaways:
- VectraRAT is a previously undocumented, full-stack Malware-as-a-Service platform built from scratch. It is not a reskin of AsyncRAT, XWorm, or QuasarRAT.
- It pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant. The two speak a proprietary binary TCP protocol using MessagePack over port 3308.
- The operator “Vectra” is a rebrand of an older identity, “Nyxel”, with a YouTube channel dating back to August 2022. Nearly four years of activity with no public reporting.
- Capabilities span both the RAT and the stealer space: hidden desktop (HVNC), keylogging, SOCKS5 relay, clipboard hijacking with regex replacement, remote shell, and mass browser credential theft, plus a UAC bypass that elevates without a prompt.
- Rented from $250 per month and delivered through the Amadey loader and ClickFix pages, with 48% of observed victim entries on corporate Windows editions, including active exfiltration from Windows Server 2025 hosts.
The research can be read here: https://socradar.io/blog/vectrarat-undocumented-stack-maas/
Download the full report (PDF) for the complete technical analysis, including the decompiled protocol internals, panel artifacts, and the full indicator set.
Related
This entry was posted on September 14, 2026 at 11:27 am and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
VectraRAT, An Undocumented Full-Stack MaaS Built From Scratch Documented By SOCRadar
SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt.
Key Takeaways:
The research can be read here: https://socradar.io/blog/vectrarat-undocumented-stack-maas/
Download the full report (PDF) for the complete technical analysis, including the decompiled protocol internals, panel artifacts, and the full indicator set.
Share this:
Like this:
Related
This entry was posted on September 14, 2026 at 11:27 am and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.