A Russian cybersecurity firm called F6 published a report this week identifying a hacker group, VantaCore, that has carried out ransomware attacks against at least seven Russian companies. The group presents itself as aligned with Ukraine. Its tools appear to be custom-built. Beyond those basics, most of the details — victim names, sectors, demands, any state connection — have not been disclosed. That combination of confirmed activity and missing detail is worth paying attention to.
What happened
F6’s report names VantaCore as the group behind the attacks. According to F6, the group has hit at least seven Russian company targets. The tooling it uses appears to have been built specifically for these operations rather than borrowed from existing ransomware kits available on criminal markets — though the technical specifics of that tooling have not been publicly disclosed beyond F6’s characterisation.
VantaCore frames itself as pro-Ukraine. Whether that framing reflects a genuine political mission, a cover story, or something in between is not answered by the available reporting. No affiliation with the Ukrainian government or any state body has been established. No demands, stolen data, or victim industries have been named publicly.
What we have, in other words, is a confirmed number — at least seven — and very little else.
Who is affected
The direct targets are Russian companies. Their identities have not been disclosed, and neither have the sectors they operate in.
F6, as the firm that identified and reported the activity, has its own position in this story. Its clients are likely the kinds of organisations being targeted. That does not make its reporting unreliable, but it is worth noting that the observer here has a stake in the story being taken seriously.
The wider affected group is harder to draw cleanly. Any organisation operating in or near a geopolitical conflict — Russian, Ukrainian, or simply a company with supply chain exposure to either — sits inside the risk perimeter of pro-Ukraine hacker group ransomware accountability disputes. Most of those organisations will not know they are there until something goes wrong.
What the real risk is
The surface risk is operational. Ransomware — software that locks your files or systems until a payment is made — disrupts businesses. Custom ransomware is harder to detect than commodity tools because security defences are often built around catalogued, known threats. Something purpose-built has no prior signature for those defences to recognise.
The deeper risk is structural. When a group frames its attacks as politically justified, the attacks become harder to categorise. Are they crime? Warfare? Activism? That ambiguity is not accidental — it is what allows attacks to continue without triggering a clear legal or diplomatic response.
There is also a precedent problem. If politically motivated ransomware against one side of a conflict is treated as acceptable — or even celebrated in some quarters — the same logic can be applied in any direction by any group that decides its cause justifies the method. What looks like accountability today can look like something else entirely tomorrow, depending on who is doing the framing.
The absence of attribution is its own risk factor. Whether VantaCore operates independently, has state backing, or has any relationship with any government body has not been established. An invisible accountability chain is, functionally, no accountability chain at all.
What to do today
This section is the reason the article exists. Here are concrete steps worth taking this week, written for people who are not security specialists.
Review your incident response plan
If your organisation operates in energy, logistics, finance, or any sector with geopolitical exposure, pull out your incident response plan and check whether it is current. If you do not have one, that is the first thing to fix. An incident response plan is simply a written record of who does what if your systems are attacked — who calls whom, which systems get isolated first, who has authority to make decisions.
Ask whether your security team can detect unfamiliar threats
Custom ransomware is designed to evade defences that rely on recognising known threats. Ask your IT or security team a direct question: Are we relying only on signature-based detection, or do we also have tools that flag unusual behaviour even from unknown software? You do not need to understand the technical answer in full. You need to know whether the question has been asked.
Test your backups
The single most effective structural defence against ransomware — of any kind, from any source — is the ability to restore your systems without paying anyone. Check that your backups exist, that they are recent, and that someone has actually tested restoring from them in the last three months. A backup that has never been tested is a backup you cannot trust.
If you report on or research this space
Note what has not been disclosed: victim identities, sectors, demands, and any state linkage. Accountability reporting requires naming those gaps explicitly. Filling them with inference produces a false picture of what is actually known.
Why this keeps happening
State-level conflict creates space for non-state actors. When governments cannot or will not hold each other accountable through formal channels — sanctions, legal mechanisms, diplomatic pressure — that gap gets filled by groups operating outside those channels entirely.
Ransomware is attractive to those groups precisely because it is deniable, scalable, and difficult to prosecute across borders. The same features that make it hard to stop make it hard to attribute with enough certainty to trigger formal consequences.
But there is a layer beneath the geopolitics. Online systems were not built with any reliable way to tie actions to identifiable, responsible parties. A group can carry out attacks, make political claims, and disappear back into the network without leaving a thread that legal or diplomatic institutions can actually pull. Even well-designed oversight struggles when there is no stable target to find. VantaCore illustrates this precisely: F6 can name the group, describe its tools in broad terms, and count its victims — but the chain of accountability that would connect those facts to a consequence does not exist in any functioning form.
VantaCore’s pro-Ukraine framing does not change that underlying dynamic. A group using political alignment as cover for attacks on civilian companies — regardless of which side those companies are on — is exploiting the same accountability vacuum that every other opportunistic actor exploits. The flag it flies is incidental to the structural problem.
Until there are functioning international mechanisms for attributing and sanctioning cyber attacks in something close to real time, this pattern will repeat. The technical sophistication of the tools will increase. The political justifications will rotate. The consequences will remain rare.
Frequently asked questions
Is VantaCore connected to the Ukrainian government?
No connection to the Ukrainian government or any state body has been established. F6’s report identifies VantaCore as presenting itself as pro-Ukraine, but that is a self-description by the group, not a finding of state affiliation. The accountability chain, if one exists, has not been made visible in any available reporting.
Why does politically motivated hacking rarely lead to prosecution?
Prosecution requires attribution — knowing with legal certainty who did something — and jurisdiction — a court that has authority over those people. Cross-border cyber attacks routinely defeat both requirements. Groups can operate from countries that will not extradite them, and the technical evidence needed to satisfy a criminal standard is difficult and slow to gather. Political framing adds another layer: it complicates whether an act is treated as crime, warfare, or something else entirely.
What makes custom ransomware more dangerous than off-the-shelf variants?
Off-the-shelf ransomware has been seen before. Security tools build up a catalogue of known threats and can recognise them when they appear. Custom ransomware — software built specifically for a campaign — has no prior record. Defences that rely on recognising known patterns will not flag it. That means it can move further into a system before anyone notices, and defenders have less prior knowledge to work from when they respond.
Related reading
Originally reported by therecord.media. This article summarises that reporting and adds practical guidance.
Scams, fraud, bots and manufactured noise keep spreading because the internet was built with no reliable way to know who anyone actually is. Every story like this one is a consequence of that gap. Everyone deserves authenticity and accountability online, and that is the mission we are working on. Subscribe to follow the work.
