// THREAT ACTOR
VANIR-GROUP_
ActiveVANIR-GROUP is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of VANIR-GROUP — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Victims by year
- 2024 3
Leak site mirrors
2 mirrors tracked, 2 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
6xdpj3sb5kekvq5ulym5qqmzsv6ektjgvpmajns3qrafgxtyxrhokfqd.onionTHIS HIDDEN SITE HAS BEEN SEIZED | Vanir Locker Ransomware snapshot · 2026-08-06 21:23 -
6xdpj3sb5kekvq5ulym5qqmzsv6ektjgvpmajns3qrafgxtyxrhokfqd.onion404 Not Found snapshot · 2026-08-06 21:12
Recent victims
The 50 most recent victims claimed by VANIR-GROUP. Total in the index: 3.
| Date listed | Victim | Description |
|---|---|---|
| 2024-07-10 | Beowulfchain | Beowulfchain is the decentralized communication and data network enabl… |
| 2024-07-10 | Qinao | Qniao is a leading provider in paper manufacturing and environmental s… |
| 2024-07-10 | Athlon | Athlon is an international provider of operational vehicle leasing and… |