Analysis of VECT 2.0 ransomware reveals critical Windows-specific implementation flaws, including buffer-size mismatches, race conditions from shared global state, and incomplete nonce retention. These defects result in files being partially encrypted, inconsistently modified, or structurally damaged, rendering the attacker's own decryptor incapable of reliable data recovery.
Vect Ransomware
3 posts
VECT: Ransomware That Can’t Decrypt VECT: Ransomware by design, Wiper by accident VECT 2.0 is a cross-platform (Windows, Linux, ESXi) Ransomware-as-a-Service that effectively functions as a wiper due to a critical cryptographic implementation flaw. Files larger than 128 KB are encrypted in chunks using raw ChaCha20-IETF, but the malware fails to save the required nonces for the first three chunks, rendering full data recovery impossible even if the ransom is paid.
TeamPCP Partners With Ransomware Group Vect to Target Open Source Supply Chains Threat actor TeamPCP has formed an alliance with the Vect Ransomware-as-a-Service (RaaS) group to weaponize recent open-source supply chain compromises. By leveraging approximately 300 GB of stolen credentials and tokens harvested from CI/CD pipelines and security tools like Trivy and LiteLLM, the groups intend to facilitate large-scale ransomware deployments across affected enterprise environments.