“The campaign’s harvested credentials were tied to the Vect ransomware operation, with affiliate access distributed through BreachForums in April 2026.”
Vect
Vect is a ransomware-as-a-service operation that emerged in late 2025 and began claiming victims in early 2026.
Profile source: Mallory opens in a new tabVect
Family profile
Vect is a ransomware-as-a-service operation that emerged in late 2025 and began claiming victims in early 2026. It provides affiliate-oriented ransomware and extortion infrastructure and has been associated with double-extortion activity, including data theft and publication of victim data. Vect has publicly partnered with TeamPCP, a financially motivated supply-chain and credential-theft actor; at least one Vect ransomware deployment has been verified using credentials sourced through TeamPCP activity.
Technical analysis of the Windows locker identified network-share and system enumeration, credential-enabled lateral-movement functions, service and process termination, Microsoft Defender and Task Manager disabling, shadow-copy deletion, and Safe Mode manipulation. It uses a libsodium ChaCha20-IETF-based file-encryption implementation and supports local and network-targeted encryption operations. The ransomware's large-file encryption routine contains a nonce-handling defect that preserves only one of several generated nonces, leaving portions of affected files unrecoverable even with the correct key. A separate buffer-handling flaw can cause some medium-sized files to be renamed without having their contents encrypted. These defects can make Vect incidents operationally resemble destructive wiper activity rather than reliable recoverable ransomware.
Vect has targeted enterprise Windows environments and has advertised Linux and VMware ESXi support, although available analysis found its Linux and ESXi builder functionality unreliable. Reported victim activity spans manufacturing, healthcare, education, information technology, and energy organizations. Its affiliate ecosystem has used anonymity-focused payment and communication mechanisms and leak-site publication to monetize intrusions.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
- Lateral Movement
- Persistence
- Reconnaissance
- Scanning
Operational record
Reported operators
Threat actors
3 named in public reportingThe current pause, combined with the Vect ransomware affiliate announcement, suggests TeamPCP has shifted primary operational focus from supply chain expansion to monetization of existing credential harvests.
Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).
Exploited software
Vulnerabilities linked to Vect
1 CVEsMITRE ATT&CK