Skip to content

Vect

Vect is a financially motivated ransomware-as-a-service operation and ransomware family that emerged in late 2025 and began claiming victims in early 2026.

Profile source: Mallory opens in a new tab

Vect

Family profile

Vect is a financially motivated ransomware-as-a-service operation and ransomware family that emerged in late 2025 and began claiming victims in early 2026. It operates a double-extortion model in which affiliates encrypt victim systems and threaten publication of stolen data through Tor-based extortion infrastructure. Vect has been publicly associated with a large-scale criminal collaboration with TeamPCP, in which TeamPCP’s software supply-chain compromises and credential theft provided downstream access later used for Vect ransomware deployment. At least one verified Vect deployment has been reported using TeamPCP-sourced credentials, indicating that the access-to-extortion pipeline was operational rather than merely advertised.

Vect is implemented in C++ and has been reported to target Windows, Linux, and VMware ESXi environments. Its Windows locker includes enterprise-focused functionality such as disabling security controls, deleting shadow copies, terminating backup, database, and productivity processes, manipulating Safe Mode boot settings, and persisting to continue execution in Safe Mode. It also supports multiple lateral movement mechanisms and can use supplied credentials to spread across networked systems and administrative channels. Reported capabilities include network share enumeration, remote task or service execution, and propagation through common Windows administration mechanisms; Linux and ESXi support has also been advertised and observed in builder functionality, although some analyses found those builds immature or unreliable.

A notable characteristic of Vect is that its encryption implementation is seriously flawed. Multiple analyses concluded that defects in nonce handling and file-processing logic can leave many files, especially larger ones, permanently unrecoverable even if the correct key is available. As a result, Vect incidents can behave operationally more like destructive wiper events than recoverable ransomware cases. This destructive outcome is generally assessed as poor implementation rather than deliberate wiper design, but the practical impact on victims is the same: ransom payment may not restore data.

Vect’s criminal ecosystem has included affiliate recruitment on Russian-language forums, low-cost affiliate onboarding, Monero-based payments, and integration with underground forum communities. Reporting has also noted possible overlaps with Devman in code strings and operational conventions, but available evidence is insufficient to treat that relationship as confirmed lineage. Victim claims have spanned multiple sectors including technology, manufacturing, healthcare, education, finance, and energy, with activity reported across several regions. Organizations exposed to TeamPCP-linked CI/CD and software supply-chain compromises face elevated risk of subsequent Vect ransomware deployment because stolen credentials, tokens, and secrets can be monetized long after the initial intrusion.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Persistence
  • Reconnaissance

Operational record

1
YARA rules
1
Ransom notes
2
Leak sites
0 available

Reported operators

Threat actors

3 named in public reporting
TeamPCP

the collaboration is between the Vect ransomware group and TeamPCP

LAPSUS$

The current pause, combined with the Vect ransomware affiliate announcement, suggests TeamPCP has shifted primary operational focus from supply chain expansion to monetization of existing credential harvests.

Vect

Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).

Exploited software

Vulnerabilities linked to Vect

1 CVEs

MITRE ATT&CK

Vect in ATT&CK

57 distinct techniques

Techniques

57 techniques
T1486 Data Encrypted for Impact T1195 Supply Chain Compromise T1649 Steal or Forge Authentication Certificates T1485 Data Destruction T1490 Inhibit System Recovery T1078 Valid Accounts T1537 Transfer Data to Cloud Account T1562.001 Disable or Modify Tools T1542.003 Bootkit T1021.006 Windows Remote Management T1046 Network Service Discovery T1021 Remote Services T1090 Proxy T1021.002 SMB/Windows Admin Shares T1195.002 Compromise Software Supply Chain T1021.003 Distributed Component Object Model T1039 Data from Network Shared Drive T1082 System Information Discovery T1083 File and Directory Discovery T1027 Obfuscated Files or Information T1059.001 PowerShell T1489 Service Stop T1135 Network Share Discovery T1059.003 Windows Command Shell T1555 Credentials from Password Stores T1547.001 Registry Run Keys / Startup Folder T1090.003 Multi-hop Proxy T1053.005 Scheduled Task T1070.004 File Deletion T1562.009 Safe Mode Boot T1561 Disk Wipe T1133 External Remote Services T1021.004 SSH T1005 Data from Local System T1112 Modify Registry T1529 System Shutdown/Reboot T1106 Native API T1482 Domain Trust Discovery T1569.002 Service Execution T1018 Remote System Discovery T1053 Scheduled Task/Job T1562 Impair Defenses T1047 Windows Management Instrumentation T1567 Exfiltration Over Web Service T1497 Virtualization/Sandbox Evasion T1570 Lateral Tool Transfer T1497.001 System Checks T1528 Steal Application Access Token T1657 Financial Theft T1583 Acquire Infrastructure T1588 Obtain Capabilities T1565 Data Manipulation T1105 Ingress Tool Transfer T1195.001 Compromise Software Dependencies and Development Tools T1190 Exploit Public-Facing Application T1566 Phishing T1027.014 Polymorphic Code

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.