A new malware platform called VectraRAT is raising concerns because cybercriminals can rent it for as little as $250 per month and use it to target Windows systems. Security researchers at SOCRadar discovered the previously undocumented Malware-as-a-Service platform and found that it provides almost everything an attacker needs, including a Windows malware implant, command-and-control infrastructure, and an operator panel. Unlike many other rented malware tools, VectraRAT was built from scratch rather than being based on leaked or modified versions of older RATs such as AsyncRAT, XWorm, or QuasarRAT.

SOCRadar said the platform was first identified on June 23, 2026, after researchers found an exposed directory containing files connected to the operation. Their investigation then expanded across more than 10 servers, dozens of malware samples, operator panel logs, and communications involving the developer. Researchers also linked the current Vectra identity to an older identity called Nyxel, which had an online presence dating back to August 2022. This suggests the developer has been active for nearly four years without previous public reporting about this particular platform.

VectraRAT combines remote-access and information-stealing capabilities in one package. Once installed on a Windows computer, it can provide attackers with a hidden desktop, remote command-line and PowerShell access, keylogging, file transfers, process discovery, clipboard manipulation, and SOCKS5 proxy functionality. The malware can also automatically collect browser credentials and search for potentially valuable files such as .env, .conf, and .config files when a victim connects to the attacker’s infrastructure. These features can give criminals both access to sensitive information and continued control over a compromised computer.

One of the most concerning features is VectraRAT’s ability to bypass Windows User Account Control, or UAC. According to the researchers, the technique can obtain a high-integrity process without displaying the normal elevation prompt to the victim. This can give an attacker greater control over a compromised machine and make further malicious activity easier. SOCRadar also found that the malware was delivered through campaigns involving the Amadey loader and ClickFix pages, a social-engineering technique that tricks users into performing actions that ultimately help install malware on their systems.

The investigation also showed that VectraRAT is not simply being used against ordinary personal computers. Of the recovered victim entries, 48% were associated with corporate Windows editions, including Windows Enterprise, Enterprise LTSC, IoT Enterprise LTSC, and Windows Server 2025. Researchers confirmed file exfiltration from compromised systems and said attackers appeared to select valuable hosts for hands-on activity afterward. The United States, Russia, and Germany were among the regions most represented in the available victim data, although SOCRadar did not identify a specific geographic or industry focus.

The discovery of VectraRAT highlights how the cybercrime market is becoming more organized and affordable. For $250 a month, attackers can obtain a professionally developed platform that combines remote access, credential theft, data collection, and infrastructure management. SOCRadar said the developer keeps control of the source code and provides the service to paying customers, while additional services were also offered for extra monthly fees. For defenders, the report provides indicators and detection guidance, while the researchers specifically warn that legitimate verification pages will never ask users to open the Run dialog and paste commands.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news