THREAT ACTOR
VANIR-GROUP_
ActiveVANIR-GROUP is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of VANIR-GROUP, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2024 3
Leak site mirrors
2 mirrors tracked, 2 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
6xdpj3sb5kekvq5ulym5qqmzsv6ektjgvpmajns3qrafgxtyxrhokfqd.onionTHIS HIDDEN SITE HAS BEEN SEIZED | Vanir Locker Ransomware snapshot · 2026-09-23 01:00 -
6xdpj3sb5kekvq5ulym5qqmzsv6ektjgvpmajns3qrafgxtyxrhokfqd.onionTHIS HIDDEN SITE HAS BEEN SEIZED | Vanir Locker Ransomware snapshot · 2026-09-23 00:25
Recent victims
The 50 most recent victims claimed by VANIR-GROUP. Total in the index: 3.
| Date listed | Victim | Description |
|---|---|---|
| 2024-07-10 | Beowulfchain | Beowulfchain is the decentralized communication and data network enabl… |
| 2024-07-10 | Qinao | Qniao is a leading provider in paper manufacturing and environmental s… |
| 2024-07-10 | Athlon | Athlon is an international provider of operational vehicle leasing and… |