Skip to content

Vect

Vect is a ransomware-as-a-service operation that emerged in late 2025 and began claiming victims in early 2026.

Profile source: Mallory opens in a new tab

Vect

Family profile

Vect is a ransomware-as-a-service operation that emerged in late 2025 and began claiming victims in early 2026. It provides affiliate-oriented ransomware and extortion infrastructure and has been associated with double-extortion activity, including data theft and publication of victim data. Vect has publicly partnered with TeamPCP, a financially motivated supply-chain and credential-theft actor; at least one Vect ransomware deployment has been verified using credentials sourced through TeamPCP activity.

Technical analysis of the Windows locker identified network-share and system enumeration, credential-enabled lateral-movement functions, service and process termination, Microsoft Defender and Task Manager disabling, shadow-copy deletion, and Safe Mode manipulation. It uses a libsodium ChaCha20-IETF-based file-encryption implementation and supports local and network-targeted encryption operations. The ransomware's large-file encryption routine contains a nonce-handling defect that preserves only one of several generated nonces, leaving portions of affected files unrecoverable even with the correct key. A separate buffer-handling flaw can cause some medium-sized files to be renamed without having their contents encrypted. These defects can make Vect incidents operationally resemble destructive wiper activity rather than reliable recoverable ransomware.

Vect has targeted enterprise Windows environments and has advertised Linux and VMware ESXi support, although available analysis found its Linux and ESXi builder functionality unreliable. Reported victim activity spans manufacturing, healthcare, education, information technology, and energy organizations. Its affiliate ecosystem has used anonymity-focused payment and communication mechanisms and leak-site publication to monetize intrusions.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Reconnaissance
  • Scanning

Operational record

1
YARA rules
1
Ransom notes
3
Leak sites
0 available

Reported operators

Threat actors

3 named in public reporting
TeamPCP

“The campaign’s harvested credentials were tied to the Vect ransomware operation, with affiliate access distributed through BreachForums in April 2026.”

LAPSUS$

The current pause, combined with the Vect ransomware affiliate announcement, suggests TeamPCP has shifted primary operational focus from supply chain expansion to monetization of existing credential harvests.

Vect

Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).

Exploited software

Vulnerabilities linked to Vect

1 CVEs

MITRE ATT&CK

Vect in ATT&CK

57 distinct techniques

Techniques

57 techniques
T1486 Data Encrypted for Impact T1195 Supply Chain Compromise T1649 Steal or Forge Authentication Certificates T1485 Data Destruction T1490 Inhibit System Recovery T1078 Valid Accounts T1537 Transfer Data to Cloud Account T1562.001 Disable or Modify Tools T1542.003 Bootkit T1021.006 Windows Remote Management T1046 Network Service Discovery T1021 Remote Services T1090 Proxy T1021.002 SMB/Windows Admin Shares T1195.002 Compromise Software Supply Chain T1021.003 Distributed Component Object Model T1039 Data from Network Shared Drive T1082 System Information Discovery T1083 File and Directory Discovery T1027 Obfuscated Files or Information T1059.001 PowerShell T1489 Service Stop T1135 Network Share Discovery T1059.003 Windows Command Shell T1555 Credentials from Password Stores T1547.001 Registry Run Keys / Startup Folder T1090.003 Multi-hop Proxy T1053.005 Scheduled Task T1070.004 File Deletion T1562.009 Safe Mode Boot T1561 Disk Wipe T1133 External Remote Services T1021.004 SSH T1005 Data from Local System T1112 Modify Registry T1529 System Shutdown/Reboot T1106 Native API T1482 Domain Trust Discovery T1569.002 Service Execution T1018 Remote System Discovery T1053 Scheduled Task/Job T1562 Impair Defenses T1047 Windows Management Instrumentation T1567 Exfiltration Over Web Service T1497 Virtualization/Sandbox Evasion T1570 Lateral Tool Transfer T1497.001 System Checks T1528 Steal Application Access Token T1657 Financial Theft T1583 Acquire Infrastructure T1588 Obtain Capabilities T1565 Data Manipulation T1105 Ingress Tool Transfer T1195.001 Compromise Software Dependencies and Development Tools T1190 Exploit Public-Facing Application T1566 Phishing T1027.014 Polymorphic Code

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.