Vice Society
Aliases: Vice Society, DEV-0832
Source profile review date: 2026-06-01
Added to the source registry: 2021-05-31 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.
Locally generated translation; linguistic review is still pending.
Executive summary
Vice Society is a blackmail actor who was best known for attacks on education and public sector, using existing ransomware variants instead of having a completely private locker.
Vice Society is relevant because CISA describes that the actor does not use a unique ransomware variant, but uses existing lockers and known techniques. Therefore, its defense value is in behavior: access, discovery, privilege usage, data extortion and abuse of education and public environments.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Management summary
Vice Society is a blackmail actor who became known mainly by attacks on education, public organisations and other sectors where downtime and data leaks have a rapid social impact. The CISA- advisory stresses that Vice Society does not use ransomware variant of unique origin. That is important: the group is not identifiable by one single locker but by method, victim choice and extortion model.
For visitors, this means that defense against Vice Society cannot rely on one hash or extension. The right focus is behavior: initial access, lateral movement, masquerading, data discovery, privilege usage, ransomware deployment and publication printing.
Vice Society is also relevant because of the overlap later mentioned in Rhysida-context, which underlines that actor profiles should remain alive: tool can change, but access patterns and victim logic remain recognizable.
Grouping and development
Vice Society operates as a cybercriminal extortion actor and does not use a fully-owned ransomware variant according to CISA. In public reports, the actor is linked to using existing families such as Zeppelin or other lockers. That makes the brand flexible: the actor can switch payloads without changing the whole operation.
The group received a lot of attention from attacks on educational institutions. Schools and education umbrellaes often have many personal data, limited security budgets, many users, a lot of external access and high pressure to recover quickly. That makes them attractive for extortion.
Because Vice Society is not attached to one locker, the profile should describe how the actor behaves. This is also more useful for visitors: they can detect behavior and take action even when the next payload has a different name.
Attack pattern from public cases
CISA connects Vice Society to TTP... like masquerading: manipulating files or attributes so they look legitimate. This fits an actor who wants to move in environments without being noticed directly. Look for binaries at unusual locations, names that resemble system processes and tooling without a clear owner.
In educational and public environments, valid accounts, remote access and weak segmentation are often important. An actor can access file shares, administration systems and servers with a lot of personal data via one account.
Data extortion is important at Vice Society. The actor can build pressure by publishing sensitive data from students, employees, citizens or clients. Therefore organizations need to search not only ransomware files but also staging, archiving and outbound traffic.
When existing ransomware variants are deployed, IOC disregardeds per incident. Therefore, a Vice Society profile should always record the payload used, ransom note, extensions and tooling per case, but structurally detect on access and behavior.
Known IOCs and artifacts
Masquerading is a concrete technique from the CISA- advisory. Suspect file names, custom metadata, placement in system-like paths and tooling that rightly looks but does not fit into baseline are important artifacts.
BecauseVice Society no unique ransomware variant used, its payload-IOC ..detect which locker, extension, note and hashes were found by incident, but do not use them as the only detection for future activity.
Strong behavior indicators include unusual remote logins, wide file-share access, new admin permissions, data compression, outgoing volume and publication claims on leak sites.
Victim pattern and lessons
Vice Society is known mainly for victim claims and incidents at educational institutions. The lesson is that civil society organisations are no less interesting to ransomware; they are attractive when data is sensitive and recovery capacity is limited.
Education environments often have many accounts, changing devices, external vendors and shared storage. This increases the chance that valid access and data discovery are possible without being noticed directly.
For public organisations, the lesson is similar. Confidential data plus public pressure gives extortionists leverage. Prevention must therefore combine identity, data and communication.
How to arm yourself against Vice Society
Inventory where sensitive education, citizen or staff data is and monitor massive access to those locations. Data governance is directly security control here.
Limit remote access and force MFA for employees, suppliers and administrators. Check dormant accounts and seasonal accounts that often persist in educational environments.
Use application control and baselining to find masquerading. A process name that looks legitimate but runs from a user directory or temporary folder deserves research.
Make sure that backups, identity and communication plans are ready before a claim appears. Vice Society-like pressure works because organizations have to respond while facts are still uncertain.
Identity, naming and attribution
For Vice Society, the operational starting point is an exact identity match. The local dossier records the following names or aliases: Vice Society, DEV-0832. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| behavior | masquerading of dropped files | CISA AA22-249A | Vice Society actors may manipulate file features to make files appear legitime. |
| behavior | use of non-unique ransomware variants | CISA AA22-249A | CISA notes Vice Society does not use a ransomware variant of unique origin. |
| targeting | education sector and public organizations | CISA AA22-249A | Strong public victimology pattern. |
| behavior | data extortion and leak-site pressure | CISA AA22-249A | Extortion model around sensitive data. |
Sources
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.