Vect is a financially motivated, Russian-speaking ransomware-as-a-service operation that emerged in late 2025 and rapidly expanded through aggressive affiliate recruitment and partnerships in the cybercrime ecosystem. The group operates a double-extortion model, combining data theft and public leak-site pressure with ransomware deployment against Windows, Linux, and VMware ESXi environments. Vect is commonly referred to as Vect or VECT. Vect became notable in 2026 for formal collaboration with TeamPCP, a separate cybercriminal group associated with large-scale software supply-chain compromises and credential theft from CI/CD, developer, and cloud environments. In this division of labor, TeamPCP appears to function as an upstream access and data supplier, while Vect provides ransomware deployment and extortion monetization. Reporting indicates that credentials and access harvested through compromises involving Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK were later used to support Vect victimization, and at least one Vect deployment has been credibly linked to TeamPCP-sourced access. Victim claims tied to this pipeline have included organizations allegedly exposed through the Trivy and LiteLLM campaign, though not all public claims are independently confirmed. Vect has also been associated with BreachForums-based affiliate enablement, including unusually broad distribution of affiliate access, suggesting an effort to industrialize ransomware operations and lower barriers to entry for less experienced criminals. The group’s business model has been described as offering high profit shares to affiliates and integrating forum-driven recruitment, escrow, and negotiation support. Technically, Vect uses purpose-built ransomware tooling written in C++ rather than commodity leaked builders, with support for cross-platform encryption operations. Observed tradecraft includes disabling or impairing security controls, terminating security, backup, database, and productivity processes, deleting shadow copies, manipulating Safe Mode boot settings, enumerating network shares and trust relationships, and moving laterally through common administrative mechanisms such as SMB, WinRM, WMI, DCOM, remote services, scheduled tasks, and SSH. Vect’s operators and affiliates rely on separate tooling or pre-stolen data for exfiltration in some intrusions, rather than a dedicated built-in exfiltration component. Multiple analyses have noted overlaps between Vect and Devman, including similarities in ransom-note style, builder strings, and lateral-movement task naming conventions. This may indicate a rebrand, spinoff, shared developers, or deliberate imitation, but the exact relationship remains unconfirmed. A significant operational characteristic of Vect is a serious flaw in its encryption implementation. Independent reporting has indicated that the ransomware can irreversibly damage many larger files, making some incidents functionally closer to destructive wiper activity than recoverable ransomware. As a result, payment does not reliably imply restoration capability. Overall, Vect represents an emerging ransomware ecosystem actor distinguished less by novel intrusion tradecraft than by its integration with upstream access brokers and supply-chain compromise operators, especially TeamPCP. Its role in converting mass credential theft and software supply-chain compromise into downstream extortion and ransomware deployment makes it a notable example of increasingly specialized, collaborative cybercrime operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware and extortion actor associated with deploying ransomware using TeamPCP-sourced credentials and monetizing downstream access through extortion infrastructure.
Ransomware operators using TeamPCP-harvested stolen credentials from compromised software supply chains to gain initial access and select victims from a prebuilt credential archive rather than conducting their own reconnaissance.
Ransomware-as-a-service operator collaborating with TeamPCP to combine credential harvesting and stolen data from supply chain compromises with Vect's ransomware deployment infrastructure.
Ransomware-as-a-service operation partnering with TeamPCP to deploy ransomware against organizations compromised through supply chain attacks and stolen credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.