Supply-Chain Victims Become VECT’s Ransomware Pool
VECT is not just selling ransomware. It is using supply-chain compromise victims as a built-in target list, which turns downstream software exposure into a faster way to find extortion targets. The standard response misses that this is victim acquisition through ecosystem compromise, not random scanning.
Check Point Research says VECT RaaS appeared in December 2025, claimed two victims in January 2026, and then formalized a partnership with TeamPCP, the group behind March 2026 supply-chain attacks on Trivy, Checkmarx KICS, LiteLLM, and Telnyx. The Linux and ESXi lockers also ignore the operator’s '--fast', '--medium', and '--secure' flags and apply hardcoded thresholds, so the advertised mode does not change the destructive behavior.
For defenders, the risk is broader than one ransomware family. A compromise in a trusted software supply chain can now feed extortion operations directly, and the same infected hosts may be hit by a locker that behaves more like a wiper than a negotiable ransomware case.