In a rare internal breach, the criminal organization behind ransomware-as-a-service (RaaS) VanHelsing has publicly leaked the source code of its platform. The incident occurred after a former associate attempted to sell the code on a cybercrime forum.

VanHelsing , a relatively new threat in the RaaS space with activity since March 2025, supports attacks on systemsand ESXi Windows, Linux, BSD, ARM , . According to Ransomware.live , the gang has so far recorded at least eight victims.
VanHelsing ransomware: Source code leaked on hacking forum
Yesterday, a user with the nickname th30c0der attempted to sell the source code of the affiliate panel, data leak Tor sites, and builders for Windows and Linux encryptors, asking for $10,000 in a post on RAMP — a well-known dark web forum.
See also: KeePass: Fake version leads to ransomware infection
“Vanhelsing ransomware source code for sale: includes TOR keys + web panel for admin + chat + file server + blog, includes everything in the database,” wrote th30c0der on the RAMP forum.
The response from VanHelsing was immediate. As first reported by cybersecurity researcher Emanuele De Lucia, the platform’s operators released the source code themselves in retaliation, calling th30c0der “a former developer trying to scam the community.”
In a surprise announcement, the ransomware-as-a-service platform said it was releasing the old source code, while also announcing the arrival of an "improved" version: VanHelsing 2.0.
However, the data leaked by the group is incomplete compared to what the former developer with the alias th30c0der. In particular, critical elements such as the Linux builder and databases, which would be particularly valuable for analysis by cybersecurity researchers and law enforcement, are missing.
BleepingComputer , and the data leak site. It also found that the Visual Studio project files are located in the “Release” folder, which is typically used for compiled binaries and build artifacts — suggesting a lack of organization in the project.
Despite its incomplete form, the leak also includes the source code for the affiliate panel, which hosts the api.php endpoint. This means that would-be criminals can adapt the code or set up their own server to fully exploit the builder.
See also: Ransomware gangs use Skitnet malware
Finally, the source code for the Windows encryptor has been leaked, which can be used to create a standalone build, the decryptor, and a loader.
Inside the code, an attempt to develop an MBR locker, which was designed to replace the master boot record with a custom bootloader that displays a lock message during system startup.

The VanHelsing leak is not the first
The VanHelsing platform source code leak joins a series of previous incidents that have significantly impacted the threat landscape. Such leaks, while rare, have proven to be a critical tool for the emergence of new ransomware groups and independent threat actors.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
One of the most notable examples occurred in June 2021, when the Babuk ransomware leaked , allowing the mass creation of encryptors and decryptors for Windows and VMware ESXi. Since then, Babuk's tool has been widely used to attack ESXi infrastructures.
In March 2022 , the source code of the notorious Conti gang was leaked , following an internal leak that revealed not only the tools but also internal communications. Many threat actors immediately leveraged the code in new ransomware campaigns.
See also: Ransomware groups exploit SAP NetWeaver vulnerability
A similar scenario occurred in September 2022, when a possibly disgruntled developer from the LockBit allegedly leaked their ransomware builder. The tool remains highly popular among attackers to this day.
As such leaks significantly facilitate the spread of the ransomware-as-a-service model, the need for constant vigilance and cooperation between cybersecurity communities and law enforcement agencies is reinforced.
The publication of VanHelsing's source code, in retaliation against the former developer, highlights the fragile balances and internal tensions in the cybercrime space, while potentially offering valuable information to authorities and security experts to identify or neutralize the VanHelsing threat in the future.
On the other hand, as with previous leaks, there is a risk that the code could be used by other groups. This means that we could soon see an increase in ransomware attacks.
Source: www.bleepingcomputer.com
