Cyber Security News

VanHelsing Ransomware Attacking Windows Systems With New Evasion Technique & File Extension

A new ransomware strain named VanHelsing has emerged, targeting Windows systems with sophisticated encryption techniques and advanced evasion tactics.

The malware, first observed on March 16, 2025, primarily focuses on government, manufacturing, and pharmaceutical sectors in France and the United States.

Upon infection, VanHelsing encrypts files on the victim’s system, appending the distinctive “.vanhelsing” extension to compromised files.

The ransomware also changes the desktop wallpaper and drops a ransom note named “README.txt” to communicate with victims.

Cyfirma researchers discovered that VanHelsing employs a double extortion strategy, not only encrypting files but also exfiltrating sensitive data such as personal details, financial reports, and other critical documents.

This two-pronged approach increases pressure on victims to pay the demanded Bitcoin ransom.

The ransomware’s technical sophistication is evident in its various persistence mechanisms and defense evasion techniques.

It utilizes Windows Management Instrumentation, scheduled tasks, and command scripting for execution.

For persistence, it employs registry run keys, Windows services, and bootkit capabilities.

VanHelsing’s desktop wallpaper (Source – Cyfirma)

The ransomware modifies the victim’s desktop wallpaper with a branded message indicating the system has been compromised.

Technical Evasion Methods

VanHelsing utilizes numerous evasion tactics that make detection challenging for security solutions.

These include direct volume access, rootkit functionality, software packing, process injection, and indicator removal.

The malware can modify registry settings, execute indirect commands, and manipulate file permissions to maintain persistence.

VanHelsing’s chat website on the Tor network (Source – Cyfirma)

VanHelsing operates a dedicated chat portal on the Tor network where victims can communicate with attackers.

The ransomware’s capabilities extend to credential theft, system discovery, and data collection from local systems and email repositories.

Security experts recommend implementing robust backup solutions, enabling multifactor authentication, patching systems regularly, and employing zero-trust architecture to mitigate risks from this emerging threat.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

5 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

16 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago