New RAT-as-a-Service 'VectraRAT' Found Targeting Corporate Windows Systems
SOCRadar's Threat Research Unit has identified VectraRAT, a remote access trojan platform that, unlike most crimeware sold online, was built entirely from scratch rather than copied from leaked code. Available for rent from $250 a month, it gives buyers hidden desktop control, keylogging, clipboard hijacking, browser credential theft, and a way to bypass Windows security prompts. The operator behind it, known as 'Vectra', is a rebrand of a group called 'Nyxel' that has been active since at least 2022 without prior public exposure.
Researchers traced the operation after discovering an exposed, publicly reachable server directory that should never have been accessible. This led them across more than ten servers and multiple campaigns, some using known malware delivery methods like Amadey and ClickFix. Nearly half of the victim data recovered came from corporate Windows systems, including one instance involving Windows Server 2025, suggesting business networks are a real target, not just home users.
The find is notable because VectraRAT represents a complete, self-contained criminal product: its server software, Windows malware, communication protocol and licensing system were all written by the same developer and sold as a subscription service with Telegram-based support. This kind of professionalised, undetected MaaS platform can be harder for security tools to catch since it doesn't match the signatures of well-known RAT families.
Key Takeaway: Australian SMBs should ensure endpoint detection tools are updated for emerging threats, restrict administrative privileges to limit the impact of UAC bypass techniques, and train staff to recognise credential theft attempts such as ClickFix-style social engineering.