Ransomware Interviews

CyberSecurityIL

Back to list

Vanir

July 2024
Q:

The Vanir group is relatively new. Your first victim appeared on your site in July 2024. Is Vanir a brand-new group or a rebrand of an old group?

A:

We are a brand new group, although some of us are veterans of groups like Knight, Karakurt, and Lockbit.

Q:

Why did you choose to start a ransomware operation instead of pursuing a regular job in the cybersecurity field? Is it solely for financial gain, or are there other motivations behind your actions?

A:

Because I'm not a sucker. The system is specifically designed to cheat you, keep you poor with savings in the bank, savings that are continually losing their value. Why spend my skills and knowledge being an idiot when I can do so much on the other side? My main motivation is financial gain.

Q:

Do your tactics include double extortion—encryption and data leak—or just data leak?

A:

My tactics include double extortion.

Q:

Do you have any boundaries or ethical considerations when selecting potential victims, such as avoiding certain countries, religions, sectors, or other criteria?

A:

I have ethical considerations. I try as much as possible to ensure my affiliates avoid hitting hospitals and research centers, etc. Personally, I have bought access for many, just to get them off the internet. I don't hit CIS countries.

Q:

How do you justify the impact your attacks have on individuals and businesses?

A:

Since we only hit corporate targets, I don't feel bad about my actions. They are all thieves, and the only reason we have access to their domains is because they're being cheap with protecting the information entrusted to them.

Q:

I assume you've heard about the drama with Lockbit (Operation Cronos). What steps are you taking to ensure the longevity and sustainability of your group in the face of increasing law enforcement pressure?

A:

Law enforcement is shit. They don't know how to perform their jobs. In the intro video for Operation Cronos, they stupidly indicated that their target was hacked with social engineering (opening a malicious file). The only people they catch are idiots that can't launder money.

Q:

What is your opinion on the current state of cybersecurity defenses in organizations?

A:

They are absolutely useless. Only take a look at ransomlook. Every day, so many companies are being ransomed. Companies cheap out, and it seems the GDPR act has to be modified to increase punishments.

Q:

What is the most common method you use to breach organizations? Do you carry out these breaches yourself, or do you acquire access through third-party access brokers?

A:

Mail spam usually works. Else software vulnerabilities are also a pretty good way to go about it.

Q:

Do you operate using a Ransomware-as-a-Service (RaaS) model? If so, how do you establish and maintain trust with your team members and affiliates?

A:

First of all, my affiliates are people that I know and trust, and naturally, there are tests that new affiliates must pass before being allowed to use my locker.

Q:

How do you choose your targets? Do you determine the financial viability and profitability of the organization before attacking them?

A:

Yes, we perform extensive reconnaissance before any attack.

Q:

Before publishing the ransom note, how long do you stay inside the victim's network?

A:

On average, we spend between 1–3 weeks on the network.

Q:

You've published 3 victims on your data leak site so far, presumably those who have not paid the ransom. Can you share the percentage of your victims who have paid the ransom versus those who have not?

A:

On average, depending on the amount of data and how critical the attack is, we usually have a 30–40% success rate in getting the payments.

Q:

Do any of you have families? How do you explain your work to them, and are they aware of what you do?

A:

A simple life eliminates these issues. Despite the fact that my main motivation is financial gain, I'm not stupid enough to go out and show off all the dirty money I've made.

Q:

How much time and financial resources do you invest in developing and maintaining your ransomware operation?

A:

I spend about 2/3rds of my day managing my group.

Q:

What advice would you give companies to help them defend against ransomware attacks?

A:

Don't be stupid, don't be cheap. We are ruthless criminals trying to make money, of course that hole in your network would be exploited. Zero trust. And PowerShell should be illegal lol.

Q:

Any last message you want to share?

A:

Anyone reading this should carefully consider their position in life. You're governed by people that do not care for you, yet you chose to follow their rules? You can do better, you can live better. You, as a living human being, deserve more. With that in mind, if you're a disgruntled employee of any corp, you can come to us. We would help you break even.

base44
Edit with Base44