VectraRAT: Custom Full-Stack MaaS Exploiting Corporate Networks
Score: 8/10

VectraRAT: Custom Full-Stack MaaS Exploiting Corporate Networks

The Vectra (formerly Nyxel) actor operates VectraRAT, a custom Go and C++ Malware-as-a-Service platform delivered via Amadey and ClickFix campaigns targeting corporate Windows environments.

Executive Summary

VectraRAT, also known as Nyxel, is an undocumented full-stack Malware-as-a-Service (MaaS) platform that has been active since at least August 2022. Unlike many competitors that reskin leaked source code, VectraRAT was built from scratch, featuring a native C++ Windows implant and a Go-based control server (VectraHub) utilizing a proprietary MessagePack-over-TCP protocol. The platform is currently rented for approximately $250 per month on cybercrime forums like HackForums and Exploit.in.

Technically, the malware distinguishes itself with a sophisticated UAC bypass utilizing debug object handle hijacking and a hidden desktop (HVNC) module. It facilitates automated credential theft and file collection immediately upon connection. Infrastructure analysis reveals a close relationship between VectraRAT C2 nodes and social engineering frameworks like ClickFix, which uses fake CAPTCHA lures to induce victims into manual PowerShell execution.

This threat is of high concern for enterprise security teams; nearly 48% of identified victims utilize corporate Windows editions, including Windows Server 2025. The malware's ability to operate as both a stealthy remote access tool and a high-volume stealer makes it a potent threat for initial access and long-term persistence within organizational networks.

Key Details

Threat Name

VectraRAT

Affects

FortiGate

Adversary

Vectra

Malware/Tools

VectraRAT, Amadey, NetSupport RAT, Vidar, PivotC2, PEEP

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure8
Technical Depth8

Sources