{"id":50244,"date":"2023-01-24T00:00:00","date_gmt":"2023-01-24T00:00:00","guid":{"rendered":"urn:uuid:6eefbdf5-e7fd-869d-ea9b-414d8fc331d8"},"modified":"2023-01-24T00:00:00","modified_gmt":"2023-01-24T00:00:00","slug":"vice-society-ransomware-group-targets-manufacturing-companies","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/","title":{"rendered":"Vice Society Ransomware Group Targets Manufacturing Companies"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/vice-society-641.jpg\"><!-- OneTrust Cookies Consent Notice start for trendmicro.com --><!-- OneTrust Cookies Consent Notice end for trendmicro.com --> <head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width\"> <meta name=\"description\" content=\"In this blog entry, we\u2019d like to highlight our findings on Vice Society, which includes an end-to-end infection diagram that we were able to create using Trend Micro internal telemetry.\"> <meta name=\"robots\" content=\"index,follow\"> <meta name=\"keywords\" content=\"endpoints,ransomware,research,articles, news, reports\"> <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge,chrome=1\"> <meta name=\"template\" content=\"article1withouthero\"> <meta property=\"article:published_time\" content=\"2023-01-24\"> <meta property=\"article:tag\" content=\"ransomware\"> <meta property=\"article:section\" content=\"research\"> <link rel=\"icon\" type=\"image\/ico\" href=\"\/content\/dam\/trendmicro\/favicon.ico\"> <link rel=\"canonical\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/a\/vice-society-ransomware-group-targets-manufacturing-companies.html\"> <title>Vice Society Ransomware Group Targets Manufacturing Companies<\/title> <link href=\"https:\/\/fonts.googleapis.com\/css?family=Open+Sans:300,300i,400,400i,600\" rel=\"stylesheet\">\n<link href=\"\/\/customer.cludo.com\/css\/296\/1798\/cludo-search.min.css\" type=\"text\/css\" rel=\"stylesheet\"> <link rel=\"stylesheet\" href=\"\/etc.clientlibs\/trendresearch\/clientlibs\/clientlib-trendresearch.min.css\" type=\"text\/css\"> <meta property=\"og:url\" content=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/a\/vice-society-ransomware-group-targets-manufacturing-companies.html\"><br \/>\n<meta property=\"og:title\" content=\"Vice Society Ransomware Group Targets Manufacturing Companies\"><br \/>\n<meta property=\"og:description\" content=\"In this blog entry, we\u2019d like to highlight our findings on Vice Society, which includes an end-to-end infection diagram that we were able to create using Trend Micro internal telemetry.\"><br \/>\n<meta property=\"og:site_name\" content=\"Trend Micro\"><br \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/vice-society-641.jpg\"><br \/>\n<meta property=\"og:locale\" content=\"en_US\"> <meta name=\"twitter:card\" content=\"summary_large_image\"><br \/>\n<meta name=\"twitter:site\" content=\"@TrendMicro\"><br \/>\n<meta name=\"twitter:title\" content=\"Vice Society Ransomware Group Targets Manufacturing Companies\"><br \/>\n<meta name=\"twitter:description\" content=\"In this blog entry, we\u2019d like to highlight our findings on Vice Society, which includes an end-to-end infection diagram that we were able to create using Trend Micro internal telemetry.\"><br \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/vice-society-641.jpg\"> <\/head> <body class=\"articlepage page basicpage context-business\" id=\"readabilityBody\" readability=\"50.220265900108\"> <!-- Page Scroll: Back to Top --> <a id=\"page-scroll\" title=\"VerticalPageScroll\" href=\"javascript:jumpScroll($(this).scrollTop());\"> <span class=\"icon-chevron-up\"><\/span> <\/a> <!-- \/* Data Layer *\/ --> <\/p>\n<div class=\"root responsivegrid\">\n<div class=\"aem-Grid aem-Grid--12 aem-Grid--default--12 \">\n<div class=\"articleBodyNoHero aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"research-layout article container\" role=\"contentinfo\">\n<article class=\"research-layout--wrapper row\" data-article-pageid=\"1094816314\">\n<div class=\"col-xs-12 col-md-12 one-column\">\n<div class=\"col-xs-12 col-md-12\" readability=\"10.753117206983\">\n<div class=\"article-details\" role=\"heading\" readability=\"41.057356608479\"> <span class=\"article-details__bar\" role=\"img\"><\/span> <\/p>\n<p class=\"article-details__display-tag\">Ransomware<\/p>\n<p class=\"article-details__description\">In this blog entry, we\u2019d like to highlight our findings on Vice Society, which includes an end-to-end infection diagram that we were able to create using Trend Micro internal telemetry.<\/p>\n<p class=\"article-details__author-by\">By: Ieriz Nicolle Gonzalez, Paul Pajares, Arianne Dela Cruz, Warren Sto.Tomas <time class=\"article-details__date\">January 24, 2023<\/time> <span>Read time:&nbsp;<\/span><span class=\"eta\"><\/span> (<span class=\"words\"><\/span> words) <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<hr class=\"research-layout-divider\"> <main class=\"main--content col-xs-12 col-md-8 col-md-push-2\"> <\/p>\n<div class=\"richText\" readability=\"39.602765556254\">\n<div readability=\"29.70207416719\">\n<p>The Vice Society&nbsp;<a href=\"https:\/\/www.trendmicro.com\/vinfo\/ph\/security\/definition\/ransomware\">ransomware<\/a>&nbsp;group&nbsp;<a href=\"https:\/\/www.scmagazine.com\/brief\/ransomware\/alleged-vice-society-ransomware-attack-against-san-francisco-bart-probed\">made headlines<\/a>&nbsp;in&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/vice-society-ransomware-gang-switches-to-new-custom-encryptor\/\">late 2022<\/a>&nbsp;and early 2023 during a spate of attacks against several targets, such as the one that affected the rapid transit system in San Francisco. Most reports have the threat actor focusing its efforts on the&nbsp;<a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252528118\/Vice-Society-ransomware-a-persistent-threat-to-education-sector\">education<\/a>&nbsp;and the&nbsp;<a href=\"https:\/\/blog.sygnia.co\/ransomware-group-that-the-health-and-education-sectors-should-look-out-for\">healthcare<\/a>&nbsp;industries. However, through Trend Micro\u2019s telemetry data, we have evidence that the group is also targeting the manufacturing sector, which means that they have capability and desire to penetrate different industries \u2014 most likely accomplished via the purchasing of compromised credentials from underground channels. We have detected the presence of Vice Society in Brazil (primarily affecting the country\u2019s manufacturing industry), Argentina, Switzerland, and Israel.&nbsp;<\/p>\n<p>Vice Society, which was initially reported to be exploiting the&nbsp;<a href=\"https:\/\/success.trendmicro.com\/dcx\/s\/solution\/000286888?language=en_US&amp;sfdcIFrameOrigin=null\">PrintNightmare vulnerability<\/a>&nbsp;in their routines, have previously&nbsp;<a href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/alerts\/aa22-249a\">deployed ransomware variants<\/a>&nbsp;such as Hello Kitty\/Five Hands and Zeppelin (the group\u2019s email has been in their ransom notes). More recently, Vice Society has been able to develop its own&nbsp;<a href=\"https:\/\/thehackernews.com\/2022\/12\/vice-society-ransomware-attackers-adopt.html\">custom ransomware builder<\/a>&nbsp;and adopt more robust encryption methods. This, and any further enhancements, could mean that the group is preparing for their own ransomware-as-a-service (RaaS) operation.<\/p>\n<p>In this blog entry, we\u2019d like to highlight our findings on Vice Society, which includes an end-to-end infection diagram that we were able to create using Trend Micro internal telemetry.&nbsp;Our detection name for this variant of Vice Society\u2019s ransomware is&nbsp;<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/Ransom.Win64.VICESOCIETY.A\/\">Ransom.Win64.VICESOCIETY.A<\/a>&nbsp;.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"138fcc\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-1.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-1.jpg\" alt=\"Figure 1. Vice Society\u2019s evolution throughout 2021 to late 2022\"> <\/a><figcaption>Figure 1. Vice Society\u2019s evolution throughout 2021 to late 2022<\/figcaption><\/figure>\n<\/p><\/div>\n<div readability=\"5.8908238446082\">\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"0e2674\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-2.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-2.jpg\" alt=\"Figure 2. Trend Micro \u2122 Smart Protection Network \u2122 (SPN) detections for Vice Society from November 2022 to January 2023 (unique endpoints)\"> <\/a><figcaption>Figure 2. Trend Micro \u2122 Smart Protection Network \u2122 (SPN) detections for Vice Society from November 2022 to January 2023 (unique endpoints)<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"c96472\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-3.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-3.jpg\" alt=\"Figure 3. Distribution of affected industries based on the Vice Society leak site\"> <\/a><figcaption>Figure 3. Distribution of affected industries based on the Vice Society leak site<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32.5\">\n<div readability=\"10\">\n<p>Based on our internal telemetry, we were able to create infection diagram for a Vice Society ransomware attack (illustrated in Figure 4). The arrival vector likely involves the exploitation of a public-facing website or abuse of compromised remote desktop protocol (RDP) credentials.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"929340\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-4.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-4.jpg\" alt=\"Figure 4. The infection chain of a Vice Society attack\"> <\/a><figcaption>Figure 4. The infection chain of a Vice Society attack<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"31.5\">\n<div readability=\"8\">\n<p>The following table shows what we were able to observe from a Vice Society attack. Note that all endpoints indicated belong to one Pointer to the GUID.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" height=\"5%\">\n<tbody readability=\"27.5\">\n<tr>\n<td>\n<p><b>Date<\/b><\/p>\n<\/td>\n<td width=\"463\" valign=\"top\">\n<p><b>Description<\/b><\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td width=\"89\" valign=\"top\">\n<p>October 28, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"7\">\n<p>Possible entry point using Cobalt Strike and the Rubeus hacktool<\/p>\n<p>Cobalt Strike connects to 57thandnormal[.]com<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"5\">\n<p>Deployed Zeppelin ransomware<\/p>\n<p>Path: C:\\mnt\\smile.exe<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"4.5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"6\">\n<p>Copied files<\/p>\n<p>kape.exe &#8211;tsource C &#8211;target RecycleBin &#8211;tdest output &#8211;zip RecycleBin_{ComputerName}&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"5\">\n<p>Deployed Mimikatz<\/p>\n<p>Path: C:\\ProgramData\\toolkiit\\{redacted}\\output\\C\\<br \/>$Recycle.Bin\\{redacted}\\$RY0DNVE.exe<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5.5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"8\">\n<p>Executed a PowerShell script (w1.ps1)<\/p>\n<p>Command: \/c powershell.exe -ExecutionPolicy Bypass -file \\\\{ComputerName}\\s$\\w1.ps1<br \/>-ExecutionPolicy Bypass -file \\\\{ComputerName}\\s$\\w1.ps1<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"8.5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"10\">\n<p>Disabled antivirus (AV) programs such as Trend Micro Apex One and Windows Defender<\/p>\n<p>\/i \\\\{ComputerName}\\netlogon\\ApexOneCloud\\agent_cloud_x64.msi \/quiet<br \/>&nbsp;add &#8220;HKLM\\Software\\Policies\\Microsoft\\Windows Defender&#8221; \/v DisableAntiVirus \/t REG_DWORD \/d 1 \/f<br \/>&nbsp;add &#8220;HKLM\\Software\\Policies\\Microsoft\\Windows Defender&#8221; \/v DisableAntiSpyware \/t REG_DWORD \/d 1 \/f<br \/>&nbsp;add &#8220;HKLM\\Software\\Policies\\Microsoft\\Windows Defender\\MpEngine&#8221; \/v MpEnablePus \/t REG_DWORD \/d 0 \/f<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"7\">\n<p>Deployed Vice Society ransomware<\/p>\n<p>Path: C:\\ProgramData\\test.exe<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"10.5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"12\">\n<p>Created Administrator account on each endpoint, add to Administrators and Remote Desktop Users localgroup<\/p>\n<p>user Administrator {password} \/add<br \/>user Administrator {password} \/add<br \/>localgroup Administrators Administrator \/ADD<br \/>localgroup &#8220;Remote Desktop Users&#8221; Administrator \/ADD<br \/>add &#8220;HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist&#8221; \/v Administrator \/t REG_DWORD \/d 0 \/f<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"8.5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"10\">\n<p>Terminated processes such as AV and security software.<\/p>\n<p>process where \u201cname like \u2018%Agent%\u2019\u201d delete<br \/>process where \u201cname like \u2018%Malware%\u2019\u201d delete<br \/>process where \u201cname like \u2018%Endpoint%\u2019\u201d delete<br \/>process where \u201cname like \u2018%sql%\u2019\u201d delete<br \/>process where \u201cname like \u2018%Veeam%\u2019\u201d delete<br \/>process where \u201cname like \u2018%Core.Service%\u2019\u201d delete<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"5\">\n<p>Exfiltrated important files<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5.5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"8\">\n<p>Multiple deployments of Vice Society ransomware was dropped in the %Temp% directory on different endpoints<\/p>\n<p>Path: C:\\windows\\temp\\svchost.exe<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"5\">\n<p>Observed file infector Neshta<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"4\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"7\">\n<p>Performed ransomware routine via $mytemp$\\svchost.exe<\/p>\n<p>&#8220;\/c vssadmin.exe Delete Shadows \/All \/Quiet<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"9.5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"10\">\n<p>Vice Society ransomware routine is performed (files are encrypted, ransom note with email contacts is dropped and files are appended with the extension .v1cesO0ciety)<\/p>\n<p>Ransom note: AllYFilesAE!<br \/>Extension: .v1cesO0ciety<br \/>Contact email of ransom operators:<br \/>876505846904@onionmail[.]org<br \/>316186524106@onionmail[.]org<br \/>v-society.official@onionmail[.]org<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"8.5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"10\">\n<p>Event viewer logs and remote session traces such as RDP and terminal services were cleared<\/p>\n<p>reg delete &#8220;&#8221;HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Default&#8221;&#8221; \/va \/f<br \/>reg delete &#8220;&#8221;HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers&#8221;&#8221; \/f<br \/>reg add &#8220;&#8221;HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Servers&#8221;&#8221;<br \/>cd %userprofile%\\documents\\<br \/>attrib Default.rdp -s -h<br \/>del Default.rdp<br \/>for \/F &#8220;&#8221;tokens=*&#8221;&#8221; %1 in (&#8216;wevtutil.exe el&#8217;) DO wevtutil.exe cl &#8220;&#8221;%1&#8243;&#8221;&#8221;<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"5\">\n<td width=\"89\" valign=\"top\">\n<p>November 12, 2022<\/p>\n<\/td>\n<td width=\"463\" valign=\"top\" readability=\"7\">\n<p>Deleted itself from the system<\/p>\n<p>&#8220;%System%\\cmd.exe&#8221; \/c del {Malware File Path}\\{Malware File Name} -&gt; nul -&gt; to delete itself<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"32\">\n<p><h5>Table 1. Date and description of the routines involved in a Vice Society attack<\/h5>\n<\/p><\/div>\n<div class=\"richText\" readability=\"43.700934579439\">\n<div readability=\"34.576563623293\">\n<p>The weaponized tool used by Vice Society is <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/tracking_cobalt_strike_a_vision_one_investigation.html\">Cobalt Strike<\/a>, which allows the group to remotely access and control the infected endpoint. The threat actor also used the Rubeus C# toolset for raw Kerberos interaction and abuse (although this is not a new technique, since it has been previously used by Ryuk, Conti, and <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/06\/13\/the-many-lives-of-blackcat-ransomware\/\">BlackCat<\/a>).<\/p>\n<p>To laterally move within the target network, Mimikatz was used to dump passwords and the Kape tool for copying files. We also observed the presence of the Zeppelin ransomware from another endpoint that also uses Kape for data exfiltration. Vice Society was known to have deployed Zeppelin before, however, perhaps due to its weaker encryption, the threat actor decided to go with custom-built ransomware.<\/p>\n<p>Vice Society will then execute a PowerShell script to create an administrator account that allows for the remote access of other endpoints and to terminate several processes such as running security software before dropping the custom-built ransomware. In most of the ViceSociety detections we also observed the presence of Neshta file infector (which can be cleaned by Trend Micro), although it is not clear how this occurred.<\/p>\n<p>Virtual servers, such as Microsoft Hyper-V, are also affected in this attack. We also found the attacker removing traces of RDP sessions such as wevtutil.exe, a technique that was <a href=\"https:\/\/twitter.com\/malwrhunterteam\/status\/1314960487507951617?lang=en\">previously used by Clop ransomware<\/a> and KillDisk.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"7b8b71\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-5a1.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-5a1.jpg\" alt=\"Figure 5. The ransomware note (top) and desktop ransom message (bottom) displayed on the victim\u2019s machine\"> <\/a> <\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"f0eb51\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-5b.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-5b.jpg\" alt=\"Figure 5. The ransomware note (top) and desktop ransom message (bottom) displayed on the victim\u2019s machine\"> <\/a><figcaption>Figure 5. The ransomware note (top) and desktop ransom message (bottom) displayed on the victim\u2019s machine<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"2a3816\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-6.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-6.jpg\" alt=\"Figure 6. The primary TOR website and mirror links\"> <\/a><figcaption>Figure 6. The primary TOR website and mirror links<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"image\">\n<figure class=\"image-figure\"> <a id=\"2eb69e\" href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-7.jpg\" target=\"_blank\" rel=\"noopener noreferrer\"> <img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/vice-society-7.jpg\" alt=\"Figure 7. Vice Society\u2019s file storage site\"> <\/a><figcaption>Figure 7. Vice Society\u2019s file storage site<\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"richText\" readability=\"33.5\">\n<div readability=\"12\">\n<p>Once the administrator account is added and established, Vice Society can terminate several processes, including security-related ones, to enable the successful deployment and execution of its ransomware on the affected endpoints.&nbsp;<b><\/b><\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"richText\">\n<div class=\"responsive-table-wrap\">\n<ul>\n<li><span class=\"rte-red-bullet\"><b>%Agent%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Malware%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Endpoint%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%sql%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Veeam%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Core.Service%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Mongo%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Backup%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%QuickBooks%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%QBDB%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%QBData%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%QBCF%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Kaspersky%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%server%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%sage%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%http%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%apache%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%segurda%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%center%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%silverlight%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%exchange%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%manage%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%acronis%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%autodesk%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%database%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%firefox%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%chrome%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%barracuda%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%arcserve%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%sprout%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%anydesk%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%protect%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%secure%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%adobe%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%java%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%logmein%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%microsoft%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%solarwinds%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%engine%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%web%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%vnc%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%teamviewer%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%OCSInventory%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%monitor%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%security%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%def%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%dev%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%office%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Framework%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%AlwaysOn%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Agent%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Malware%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Endpoint%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%sql%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Veeam%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%acronis%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%autodesk%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%database%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%adobe%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%java%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%logmein%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%microsoft%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%solarwinds%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%engine%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%QBDB%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%QBData%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%QBCF%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Kaspersky%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%server%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%sage%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%http%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%apache%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%web%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%vnc%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%AlwaysOn%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Framework%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%sprout%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%firefox%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%chrome%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%barracuda%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%arcserve%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%exchange%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%manage%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Core.Service%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Mongo%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%Backup%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%QuickBooks%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%teamviewer%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%OCSInventory%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%monitor%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%security%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%def%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%dev%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%office%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%anydesk%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%protect%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%secure%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%segurda%<\/b><\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>%center%<\/b><\/span><\/li>\n<li>&nbsp;<span class=\"rte-red-bullet\"><b>%silverlight%<\/b><\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div class=\"richText\" readability=\"37.242857142857\">\n<div readability=\"22.628571428571\">\n<p>Vice Society seems to be constantly improving their capabilities, managing to build their own custom-built ransomware while also continuing to employ toolsets such as Cobalt Strike and malware such as Zeppelin and Hello Kitty\/FiveHands to enhance their routines. Furthermore, the use of the Kape tool can speed up the identification of important files from a computer. Given what we know of the group\u2019s technical knowledge and their willingness to target several different industries and regions, we can expect them to remain a significant player in the ransomware landscape and a threat that organizations must keep track of moving forward.<\/p>\n<p>A multilayered approach can help organizations guard possible entry points into their system, such as endpoints, emails, web, and networks. The following security solutions can detect malicious components and suspicious behavior, which can help protect enterprises.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/detection-response.html\">Trend Micro Vision One\u2122<\/a>&nbsp;provides multilayered protection and behavior detection, which helps block questionable behavior and tools early on before the ransomware can do irreversible damage to the system.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/cloud-one-workload-security.html\">Trend Micro Cloud One\u2122<\/a>&nbsp;Workload Security protects systems against both known and unknown threats that exploit vulnerabilities. This protection is made possible through techniques such as virtual patching and machine learning.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection\/sps\/email-and-collaboration\/email-inspector.html\">Trend Micro\u2122 Deep Discovery\u2122<\/a>&nbsp;Email Inspector employs custom sandboxing and advanced analysis techniques to effectively block malicious emails, including phishing emails that can serve as entry points for ransomware.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection\/sps\/endpoint.html\">Trend Micro Apex One\u2122<\/a>&nbsp;offers next-level automated threat detection and response against advanced concerns such as fileless threats and ransomware, ensuring the protection of endpoints.<br \/>&nbsp;<\/span><\/li>\n<\/ul>\n<p>The indicators of compromise for this blog entry can be found <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/23\/vice-society-ransomware-group-targets-manufacturing-companies\/iocs-vice-society-ransomware-group-targets-manufacturing-companies-full.txt\">here<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"tag--list\">\n<p>Tags<\/p>\n<\/section>\n<p> <\/main> <\/article>\n<\/div>\n<\/div><\/div>\n<\/div>\n<p> <!-- \/* Core functionality javascripts, absolute URL to leverage Akamai CDN *\/ --> <!--For Modal-start--> <\/p>\n<p> <span>sXpIBdPeKzI9PC2p0SWMpUSM2NSxWzPyXTMLlbXmYa0R20xk<\/span> <\/p>\n<p> <!--For Modal-end--> <!-- Go to www.addthis.com\/dashboard to customize your tools --> <\/body> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/a\/vice-society-ransomware-group-targets-manufacturing-companies.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this blog entry, we\u2019d like to highlight our findings on Vice Society, which includes an end-to-end infection diagram that we were able to create using Trend Micro internal telemetry. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":50245,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9508,9539,9509],"class_list":["post-50244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-endpoints","tag-trend-micro-research-ransomware","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vice Society Ransomware Group Targets Manufacturing Companies 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vice Society Ransomware Group Targets Manufacturing Companies 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-01-24T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/vice-society-641.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Vice Society Ransomware Group Targets Manufacturing Companies\",\"datePublished\":\"2023-01-24T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/\"},\"wordCount\":1558,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/vice-society-ransomware-group-targets-manufacturing-companies.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Ransomware\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/\",\"name\":\"Vice Society Ransomware Group Targets Manufacturing Companies 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/vice-society-ransomware-group-targets-manufacturing-companies.jpg\",\"datePublished\":\"2023-01-24T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/vice-society-ransomware-group-targets-manufacturing-companies.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/vice-society-ransomware-group-targets-manufacturing-companies.jpg\",\"width\":1430,\"height\":524},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/vice-society-ransomware-group-targets-manufacturing-companies\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Vice Society Ransomware Group Targets Manufacturing Companies\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vice Society Ransomware Group Targets Manufacturing Companies 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/","og_locale":"en_US","og_type":"article","og_title":"Vice Society Ransomware Group Targets Manufacturing Companies 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-01-24T00:00:00+00:00","og_image":[{"url":"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/vice-society-641.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Vice Society Ransomware Group Targets Manufacturing Companies","datePublished":"2023-01-24T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/"},"wordCount":1558,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/01\/vice-society-ransomware-group-targets-manufacturing-companies.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Endpoints","Trend Micro Research : Ransomware","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/","url":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/","name":"Vice Society Ransomware Group Targets Manufacturing Companies 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/01\/vice-society-ransomware-group-targets-manufacturing-companies.jpg","datePublished":"2023-01-24T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/01\/vice-society-ransomware-group-targets-manufacturing-companies.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2023\/01\/vice-society-ransomware-group-targets-manufacturing-companies.jpg","width":1430,"height":524},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/vice-society-ransomware-group-targets-manufacturing-companies\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Vice Society Ransomware Group Targets Manufacturing Companies"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=50244"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50244\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/50245"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=50244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=50244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=50244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}