Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Aug 03, 2022 | Updated Apr 03, 2023

Ransom:Win32/VSocCrypt.PA!MTB

Detected by Microsoft Defender Antivirus

Aliases: Vice Society (other)

Summary

Microsoft Defender Antivirus detects and removes this threat.

This threat has been observed on ransomware and extortion campaigns impacting the global education sector, particularly in the United States, by a threat actor we track as DEV-0832, also known as Vice Society. Shifting ransomware payloads over time from BlackCat, QuantumLocker, and Zeppelin, DEV-0832’s latest payload is a Zeppelin variant that includes Vice Society-specific file extensions, such as .v-s0ciety, .v-society, and, most recently, .locked. In several cases, Microsoft assesses that the group did not deploy ransomware and instead possibly performed extortion using only exfiltrated stolen data.

For more information and guidance from Microsoft about this threat, read the following blogs:

There is no one-size-fits-all response if you have been targeted by ransomware. To recover files, you can restore backups. There is no guarantee that paying the ransom will give you access to your files.

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.

You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.

Follow us