Cyberattackers Now Have a $250 Monthly Malware-For-Hire Option for Windows Networks
A sophisticated malware-as-a-service (MaaS) platform has been discovered by researchers at SOCRadar, which offers cybercriminals comprehensive remote access to compromised Windows networks for a relatively modest monthly fee of $250. The platform, dubbed VectraRAT, is a full-stack solution that includes a custom-built Windows implant, command-and-control (C2) infrastructure, and an operator panel – all designed from scratch by the same developer.
VectraRAT’s operator has been active for nearly four years without detection, but was only recently uncovered by SOCRadar researchers in June. The platform is marketed as a comprehensive solution for cyberattacks, with capabilities that include user account control (UAC) bypass, proprietary protocols for C2 communication, and the ability to provide attackers with hidden desktops, remote command-line access, keylogging, file transfer, process discovery, clipboard manipulation, and SOCKS5 proxy functionality.
What sets VectraRAT apart from other MaaS platforms is its complete custom-built design. Unlike many malware solutions that are based on existing code or modified versions of popular tools, VectraRAT’s developer has built every layer of the platform from scratch – including the Linux control server, Windows implant, protocol between them, and even the licensing system designed to keep operators paying.
“This is a game-changer for cyberattackers,” says Denis Calderone, chief technology officer at Suzu Labs. “VectraRAT is incredibly sophisticated, with features that are usually found in high-end malware solutions. And at $250 per month, it’s priced like any mid-tier software-as-a-service application.”
The platform also includes add-on services such as fully detectable crypting services, which can be purchased for between $100 and $350 per month, or a bundled package with the crypting and other services quoted above $2,000. The developer has even demonstrated scan results against named antivirus (AV) products, while noting that detection varies by product, version, and configuration.
VectraRAT is delivered through Amadey loader and ClickFix pages – popular social engineering vectors for attackers. Once installed, it provides attackers with a hidden foothold in the compromised machine, allowing them to collect sensitive data, steal additional credentials, access sensitive files, and potentially move laterally within the environment.
This development highlights the growing sophistication of malware-as-a-service platforms and their increasing affordability for cyberattackers. As Calderone notes, “It’s becoming less expensive to develop a cybercriminal business with custom malware than it is to pay off a mortgage.”
For organizations, this means that they need to be vigilant in protecting their networks from these types of threats. This includes implementing robust endpoint security measures, keeping software up-to-date, and conducting regular vulnerability assessments to identify potential entry points for attackers. By taking these steps, organizations can reduce the risk of falling victim to sophisticated malware attacks like VectraRAT.
Source: Dark Reading — 2026-09-15