VFVCT
VFVCT, also referred to as V For Vendetta Cyber Team, is a threat actor operating within a broader collaborative cybercrime ecosystem tied to THE PERSEPHONE leak platform. The content links VFVCT to THE PERSEPHONE through a BreachForums post by the user VFVCT that referred to the Persephone domain as "our website," repeated sharing of the domain in VFVCT-linked Telegram channels, and prominent references to VFVCT on the Persephone landing page. THE PERSEPHONE presented itself as a prototype leak platform and described cooperation among VFVCT, RasCorp Group, and ClayRat/CrackRat Zone Clay under the banner of "United Cyber Operations," indicating that VFVCT participated in a multi-group alliance rather than acting solely through a standalone leak site. The group used Telegram channels and groups as a communication and coordination layer for recruitment, leak promotion, operational messaging, and discussion of future database releases. A private Telegram group titled Project_Vendetta referenced V For Vendetta Cyber Team and listed contact points including a Telegram bot and email addresses. A separate Telegram channel presented itself as a backup channel for VFVCT. Messages in these channels discussed hacking activities, recruitment, geopolitical commentary, and upcoming data releases, including a planned database release at the end of Ramadan. One message claimed campaigns targeting South Korea, India, and Indonesia and asserted possession of large datasets associated with those countries. The content also indicates that VFVCT maintained broader supporting infrastructure beyond Telegram, including references to a GitHub Pages site described by the actors as part of their DLS or ransomware-related infrastructure, a TOX ID, a Session messenger ID, and a separate website hosted through a free web hosting provider. A VFVCT channel message invited technically skilled individuals to contact the group regarding ransomware partnerships. Within the alliance described in the content, VFVCT was characterized as contributing operational and strategic capabilities, while RasCorp Group handled business operations and coordination and CrackRat Zone Clay provided multifunctional tools. Known aliases and associated names directly mentioned in the content include VFVCT and V For Vendetta Cyber Team. Associated allied groups mentioned are RasCorp Group and ClayRat/CrackRat Zone Clay.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇮🇱 Israel
- 🇰🇷 South Korea
- 🇮🇳 India
- 🇮🇩 Indonesia
Where they're from
Attributed origin per open-source reporting.
- MY
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Member of a Telegram-based cyber alliance with RasCorp and CrackRat Zone Clay, contributing operational and strategic capabilities to the broader ecosystem.
Operates and promotes THE PERSEPHONE leak platform, uses Telegram channels for recruitment, coordination, and promotion of leak activities, and seeks ransomware partnerships within a collaborative ecosystem.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.