Executive Summary
VectraRAT, also known as Nyxel, is an undocumented full-stack Malware-as-a-Service (MaaS) platform that has been active since at least August 2022. Unlike many competitors that reskin leaked source code, VectraRAT was built from scratch, featuring a native C++ Windows implant and a Go-based control server (VectraHub) utilizing a proprietary MessagePack-over-TCP protocol. The platform is currently rented for approximately $250 per month on cybercrime forums like HackForums and Exploit.in.
Technically, the malware distinguishes itself with a sophisticated UAC bypass utilizing debug object handle hijacking and a hidden desktop (HVNC) module. It facilitates automated credential theft and file collection immediately upon connection. Infrastructure analysis reveals a close relationship between VectraRAT C2 nodes and social engineering frameworks like ClickFix, which uses fake CAPTCHA lures to induce victims into manual PowerShell execution.
This threat is of high concern for enterprise security teams; nearly 48% of identified victims utilize corporate Windows editions, including Windows Server 2025. The malware's ability to operate as both a stealthy remote access tool and a high-volume stealer makes it a potent threat for initial access and long-term persistence within organizational networks.
