---
title: Vice Society Ransomware Attackers Adopt Robust Encryption Methods
metaTitle: "Ransomware Attackers Adopt Robust Encryption"
slug: vice-society-new-encryption
date: "2022-12-23T12:00:00-06:00"
image:
  src: "https://cdn.securelogix.dev/slx/images/vice-society-ransomware-attackers-adopt-robust-encryption-methods.webp"
sourcePublisher:
  name: The Hacker News
  url: thehackernews.com
sourceArticle:
  url: "https://thehackernews.com/2022/12/vice-society-ransomware-attackers-adopt.html"
legacySlug: vice-society-ransomware-attackers-adopt-robust-encryption-methods
tags: [Phishing, Ransom, TOAD, Vishing]
status: published
---

The Vice Society ransomware actors have switched to yet another custom ransomware payload in their recent attacks aimed at a variety of sectors.

“This ransomware variant, dubbed ’PolyVice,’ implements a robust encryption scheme, using NTRUEncrypt and ChaCha20-Poly1305 algorithms,” SentinelOne researcher Antonio Cocomazzi said in an analysis.

Vice Society, which is tracked by Microsoft under the moniker DEV-0832, is an intrusion, exfiltration, and extortion hacking group that first appeared on the threat landscape in May 2021.

Unlike other ransomware gangs, the cybercrime actor does not use file-encrypting malware developed in-house. Instead, it’s known to deploy third-party lockers such as Hello Kitty, Zeppelin, and RedAlert ransomware in their attacks.

Per SentinelOne, indications are that the threat actor behind the custom-branded ransomware is also selling similar payloads to other hacking crews based on PolyVice’s extensive similarities to ransomware strains Chily and SunnyDay...
