A New Ransomware Threat: VanHelsing’s Rapid Expansion

Red | Attack Report
Download PDF

VanHelsing is a ransomware-as-a-service (RaaS) operation that emerged on March 7, 2025, quickly gaining attention in the cybercrime world. It uses double extortion tactics, encrypting files while threatening to leak stolen data, with ransom demands reaching up to $500,000 per victim. Operating on an affiliate model, it allows cybercriminals to join with a $5,000 deposit, offering them 80% of the ransom while operators take 20%. Primarily targeting Windows, it also claims compatibility with Linux, BSD, ARM, and VMware ESXi. Within two weeks, it had already infected three organizations, highlighting its rapid spread and the urgent need for strong cybersecurity defenses.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs