Vect is a financially motivated, Russian-speaking ransomware-as-a-service operation that emerged in late December 2025 and rapidly expanded through aggressive affiliate recruitment and double-extortion operations. It is commonly referred to as Vect or the Vect Ransomware Group. The operation has been associated with a formal partnership with TeamPCP, in which TeamPCP’s large-scale software supply-chain compromises and credential theft activity provided upstream access and stolen secrets that Vect could monetize through ransomware deployment and data-leak extortion. Vect targets Windows, Linux, and VMware ESXi environments and operates a multi-platform locker written in C++. Reported tradecraft includes pre-encryption data theft, publication on a Tor-based leak site, disabling security controls, deleting shadow copies, terminating security, backup, database, and productivity processes, manipulating Safe Mode boot settings, and lateral movement through common enterprise administration channels including SMB, WinRM, WMI, DCOM, remote services, scheduled tasks, and SSH. The group has also been observed supporting affiliate-supplied credentials for remote access abuse. Victimology reported in early 2026 spans technology, manufacturing, healthcare, education, financial services, energy, and other sectors across multiple regions, with notable concentration in the United States and Brazil. A defining feature of Vect’s 2026 activity is its integration into a broader criminal ecosystem. The group advertised on Russian-language cybercrime forums, offered high affiliate profit shares, waived some fees for CIS-based participants, and later expanded recruitment through a partnership with BreachForums that reportedly lowered barriers to entry for a large pool of would-be affiliates. Public reporting also notes possible technical and operational overlap with Devman, including similarities in ransom-note style and internal naming conventions, though any direct lineage remains unconfirmed. Vect’s collaboration with TeamPCP marked a significant escalation in ransomware operations by industrializing the path from software supply-chain compromise to credential theft, downstream access, extortion, and ransomware deployment. TeamPCP has been linked to compromises involving Trivy, Checkmarx KICS, LiteLLM, Telnyx, and related CI/CD and package ecosystems, with stolen credentials later used in at least one confirmed Vect deployment. This model effectively turned poisoned developer and security tooling into a scalable initial-access pipeline for ransomware monetization. Reporting also links Vect to victim claims and data publication tied to organizations exposed through the TeamPCP campaign. Vect should also be noted for a serious implementation flaw in its encryption routine. Multiple researchers reported that the malware’s ChaCha20-based intermittent encryption contains a nonce-handling defect that can permanently corrupt many larger files, making incidents operationally closer to destructive wiper events than reliably recoverable ransomware attacks. As a result, victims cannot assume that payment will enable restoration even if the operators cooperate. Known aliases and related naming include VECT, VECT 2.0, Vect operators, and Vect Ransomware Group. The group is best understood as an emerging but consequential RaaS actor whose significance derives not only from its locker, but from its partnerships, affiliate scaling model, and role in monetizing supply-chain-derived access at enterprise scale.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware and extortion actor associated with deploying ransomware using TeamPCP-sourced credentials and monetizing downstream access through extortion infrastructure.
Ransomware operators using TeamPCP-harvested stolen credentials from compromised software supply chains to gain initial access and select victims from a prebuilt credential archive rather than conducting their own reconnaissance.
Ransomware-as-a-service operator collaborating with TeamPCP to combine credential harvesting and stolen data from supply chain compromises with Vect's ransomware deployment infrastructure.
Ransomware-as-a-service operation partnering with TeamPCP to deploy ransomware against organizations compromised through supply chain attacks and stolen credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.