SOCRADAR researchers have uncovered VectraRAT, a previously undocumented malware-as-a-service platform costing operators $250 per month. Unlike many crimeware services that modify existing malware, VectraRAT’s Linux command-and-control server, Windows implant, communications protocol, licensing system and operator panel were reportedly built from scratch by one developer.
The service has allegedly operated for nearly four years, previously under the name Nyxel, and includes optional crypting services costing $100–$350 per month or bundled packages priced above $2,000.
The Windows implant can be delivered through the Amadey loader and ClickFix social-engineering pages. Once installed, it supports remote desktop access, CMD and PowerShell control, keylogging, file transfers, process discovery, clipboard manipulation and SOCKS5 proxying. It also collects browser credentials and searches for `.env`, `.conf` and `.config` files. Its UAC-bypass capability can obtain a high-integrity process without the normal elevation prompt.
SOCRadar found that 48% of victim entries involved corporate Windows editions, including Windows Enterprise, Enterprise LTSC, IoT Enterprise LTSC and Windows Server 2025, and confirmed file exfiltration. The US, Russia and Germany were most represented in the victim data, although no specific sector or geographic targeting was identified.
SOCRadar supplied indicators including a C2 override file, outbound TCP port 3308 activity linked to auto-elevation abuse, a debug API sequence and hidden PowerShell. It also warned that legitimate verification pages do not ask users to open the Windows Run dialogue and paste commands, a technique associated with ClickFix delivery.