The Vice Society threat group was discovered targeting multiple sectors including manufacturing companies in Brazil.
The actor has been active since 2021 deploying variants from the Hello Kitty, Five Hands, and Zeppelin ransomware families.
In late 2022 the adversary developed and deployed their own custom ransomware known as PolyVice.
The malicious software not only encrypts files but also exfiltrates sensitive data and deletes volume shadow copies to hinder recovery.