the collaboration is between the Vect ransomware group and TeamPCP
Vect
Vect is a financially motivated ransomware-as-a-service operation and ransomware family that emerged in late 2025 and began claiming victims in early 2026.
Profile source: Mallory opens in a new tabVect
Family profile
Vect is a financially motivated ransomware-as-a-service operation and ransomware family that emerged in late 2025 and began claiming victims in early 2026. It operates a double-extortion model in which affiliates encrypt victim systems and threaten publication of stolen data through Tor-based extortion infrastructure. Vect has been publicly associated with a large-scale criminal collaboration with TeamPCP, in which TeamPCP’s software supply-chain compromises and credential theft provided downstream access later used for Vect ransomware deployment. At least one verified Vect deployment has been reported using TeamPCP-sourced credentials, indicating that the access-to-extortion pipeline was operational rather than merely advertised.
Vect is implemented in C++ and has been reported to target Windows, Linux, and VMware ESXi environments. Its Windows locker includes enterprise-focused functionality such as disabling security controls, deleting shadow copies, terminating backup, database, and productivity processes, manipulating Safe Mode boot settings, and persisting to continue execution in Safe Mode. It also supports multiple lateral movement mechanisms and can use supplied credentials to spread across networked systems and administrative channels. Reported capabilities include network share enumeration, remote task or service execution, and propagation through common Windows administration mechanisms; Linux and ESXi support has also been advertised and observed in builder functionality, although some analyses found those builds immature or unreliable.
A notable characteristic of Vect is that its encryption implementation is seriously flawed. Multiple analyses concluded that defects in nonce handling and file-processing logic can leave many files, especially larger ones, permanently unrecoverable even if the correct key is available. As a result, Vect incidents can behave operationally more like destructive wiper events than recoverable ransomware cases. This destructive outcome is generally assessed as poor implementation rather than deliberate wiper design, but the practical impact on victims is the same: ransom payment may not restore data.
Vect’s criminal ecosystem has included affiliate recruitment on Russian-language forums, low-cost affiliate onboarding, Monero-based payments, and integration with underground forum communities. Reporting has also noted possible overlaps with Devman in code strings and operational conventions, but available evidence is insufficient to treat that relationship as confirmed lineage. Victim claims have spanned multiple sectors including technology, manufacturing, healthcare, education, finance, and energy, with activity reported across several regions. Organizations exposed to TeamPCP-linked CI/CD and software supply-chain compromises face elevated risk of subsequent Vect ransomware deployment because stolen credentials, tokens, and secrets can be monetized long after the initial intrusion.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Extortion
- Lateral Movement
- Persistence
- Reconnaissance
Operational record
Reported operators
Threat actors
3 named in public reportingThe current pause, combined with the Vect ransomware affiliate announcement, suggests TeamPCP has shifted primary operational focus from supply chain expansion to monetization of existing credential harvests.
Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).
Exploited software
Vulnerabilities linked to Vect
1 CVEsMITRE ATT&CK