VectraRAT, An Undocumented Full-Stack MaaS Built From Scratch Documented By SOCRadar

SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt.

Key Takeaways: 

  • VectraRAT is a previously undocumented, full-stack Malware-as-a-Service platform built from scratch. It is not a reskin of AsyncRAT, XWorm, or QuasarRAT.
  • It pairs a Go control server called VectraHub, with a Vue3 operator panel compiled into the binary, with a native C++ Windows implant. The two speak a proprietary binary TCP protocol using MessagePack over port 3308.
  • The operator “Vectra” is a rebrand of an older identity, “Nyxel”, with a YouTube channel dating back to August 2022. Nearly four years of activity with no public reporting.
  • Capabilities span both the RAT and the stealer space: hidden desktop (HVNC), keylogging, SOCKS5 relay, clipboard hijacking with regex replacement, remote shell, and mass browser credential theft, plus a UAC bypass that elevates without a prompt.
  • Rented from $250 per month and delivered through the Amadey loader and ClickFix pages, with 48% of observed victim entries on corporate Windows editions, including active exfiltration from Windows Server 2025 hosts.

The research can be read here: https://socradar.io/blog/vectrarat-undocumented-stack-maas/

Download the full report (PDF) for the complete technical analysis, including the decompiled protocol internals, panel artifacts, and the full indicator set.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading