Actor Profile

🏹 VanHelsing — Ransomware

VanHelsing is a multi-platform RaaS operation that launched on March 7, 2025, requiring a $5,000 affiliate deposit and splitting ransoms 80/20, supporting Windows, Linux, BSD, ARM, and ESXi targets, reaching at least five victims across the US, France, Italy, and Australia within its first two months.

Classification

Ransomware

Leak-site victims

8
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (8)

VictimCountryPublishedDomain
caschile.cl CL 2025-04-05T23:41:37.860423+00:00 caschile.cl
attorneykohm.com US 2025-03-31T23:40:46.405394+00:00 attorneykohm.com
alertenterprise.com US 2025-03-31T23:15:28.993793+00:00 alertenterprise.com
compumedics.com.au AND neuromedicalsupplies.com AU 2025-03-26T22:42:26.319393+00:00 compumedics.com.au
studiocdlvallone.it IT 2025-03-24T19:44:35.308019+00:00 studiocdlvallone.it
www.medsrx.com US 2025-03-19T16:45:53.578753+00:00 medsrx.com
Atos-racks.com FR 2025-03-18T22:41:28.692844+00:00 Atos-racks.com
www.cityofbellville.com US 2025-03-17T12:55:44.274069+00:00 cityofbellville.com

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php