Ransomware · 155 giorni fa
VECT is not just selling ransomware. It is using supply-chain compromise victims as a built-in target list, which turns downstream software exposure into a faster way to find extortion targets. The standard response misses that this is victim acquisition through ecosystem compromise, not random scanning.
Check Point Research says VECT RaaS appeared in December 2025, claimed two victims in January 2026, and then formalized a partnership with TeamPCP, the group behind March 2026 supply-chain attacks on Trivy, Checkmarx KICS, LiteLLM, and Telnyx. The Linux and ESXi lockers also ignore the operator’s '--fast', '--medium', and '--secure' flags and apply hardcoded thresholds, so the advertised mode does not change the destructive behavior.
For defenders, the risk is broader than one ransomware family. A compromise in a trusted software supply chain can now feed extortion operations directly, and the same infected hosts may be hit by a locker that behaves more like a wiper than a negotiable ransomware case.
6 fonti che coprono questa storia
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
The emerging ransomware has been deployed in the TeamPCP supply chain attacks, but victims should think twice before paying for a decryptor.
Critical Flaw Turns Vect Ransomware into Data Destroying Wiper
The Vect 2.0 ransomware wipes large files instead of merely encrypting them, making recovery impossible – even for the attackers
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
VECT 2.0 destroys files over 131KB due to nonce flaw, launched December 2025, making ransom payments useless.
Don’t pay VECT a ransom - your big files are likely gone
: 'Full recovery is impossible for anyone, including the attacker'
Broken VECT 2.0 ransomware acts as a data wiper for large files
Researchers are warning that the VECT 2.0 ransomware has a problem in the way it handles encryption nonces that leads to permanently destroying larger files rather than encrypt them.
VECT: Ransomware by design, Wiper by accident - Check Point Research
Key Takeaways Background VECT Ransomware is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum.
Part of the PlainSec briefing for 2026-04-30