Vice Society Ransomware

Description Summary

Vice Society was a ransomware extortion group active from 2021 to early 2024, best known for relentless attacks on the education sector — schools, school districts, and universities. Rather than developing their own encryptor, they typically deployed third-party ransomware (Hello Kitty, Zeppelin, PolyVice, RedAlert). The group is assessed to have rebranded as Rhysida in 2023.

Threat Actor

Russian-speaking actor. Heavy overlap with Rhysida.

Technical Indicators

Encryption Extension
.v-society / .locked / payload-dependent
Encryption Algorithm
ChaCha20-Poly1305 + NTRUEncrypt (PolyVice variant)
Ransom Note Name
AllYFilesAE / payload-dependent
Targeted Industries
Education (K-12 and higher ed), Healthcare, Government
First Seen
May 2021
Last Seen
Q1 2024 (transition to Rhysida)
Geographical Location
United States, United Kingdom, Spain, Brazil

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop