Vect is a financially motivated ransomware-as-a-service operation that emerged in late December 2025 and began claiming victims in early 2026. It is associated with a double-extortion model in which data theft precedes encryption and victim data may be published through leak infrastructure if ransom demands are not met. The malware is described as a purpose-built C++ family supporting Windows, Linux, and VMware ESXi environments, with enterprise-oriented functionality including process termination, shadow-copy and recovery inhibition, Safe Mode boot manipulation on Windows, network reconnaissance, and lateral movement through SMB, WinRM, remote service execution, and related administrative mechanisms. Public reporting also describes support for credential-assisted deployment and targeting of virtualized infrastructure, including handling of virtual disk files.
Vect became especially notable in 2026 through an operational partnership with TeamPCP, a financially motivated threat group involved in large-scale software supply-chain compromises and credential theft. In that model, TeamPCP harvested cloud, CI/CD, package-publishing, and other non-human credentials from poisoned developer and security tooling, while Vect provided ransomware deployment and extortion infrastructure. At least one verified Vect deployment has been linked to TeamPCP-sourced credentials, and multiple victim claims were subsequently associated with that access pipeline. This partnership reflects a shift from direct intrusion toward post-compromise victim selection using previously stolen credentials.
Vect’s criminal ecosystem includes affiliate recruitment on Russian-language forums, Tor-based negotiation and leak infrastructure, and Monero-centric payment handling. Reporting indicates broad affiliate enablement and unusually low barriers to entry relative to many established ransomware programs. Some analyses also note possible overlaps with Devman based on code and operational similarities, but this relationship is not conclusively established.
A major technical characteristic of Vect is a serious implementation flaw in its encryption routine. Multiple analyses concluded that versions of Vect, particularly Vect 2.0, can permanently destroy larger files instead of reliably encrypting them, making affected data unrecoverable even if a victim pays. As a result, incidents involving Vect should be treated operationally as hybrid ransomware-and-wiper events rather than conventional recoverable ransomware cases. The destructive outcome is generally assessed as the result of poor implementation rather than an intentionally designed wiper, but the practical impact on victims can be the same.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VECERT reported on April 2, 2026 that the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Vect is a ransomware-as-a-service (RaaS) operation that began recruiting affiliates on Russian-language cybercrime forums in late December 2025 and started claiming victims in early January 2026.
Update 002 covered developments through March 27, including the Telnyx PyPI compromise and Vect ransomware partnership.
Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).
29 distinct techniques documented for this family, organized by ATT&CK tactic.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
Between February and March 2026, TeamPCP tampered with four widely used open source packages that development teams rely on daily.
Between March 19 and March 24, 2026, TeamPCP compromised the Trivy GitHub Actions workflow, the Checkmarx KICS package, the LiteLLM PyPI distribution (versions 1.82.7 and 1.82.8), and the Telnyx Python SDK. A credential-harvesting payload fired during CI/CD execution in downstream organizations.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
A double XOR routine intended to keep these flags encrypted at rest accidentally cancels itself out, leaving them as plaintext strings inside the binary.
Built-in LAN scanning enables automated network reconnaissance following initial access.
The Linux and ESXi variants implement CIS geofencing by reading LANG, LC_ALL, and /etc/timezone.
Impact Data Destruction T1485 Implementation defects can irreversibly corrupt files, producing a wiper-like effect regardless of intent.
Update 004 covered developments through March 30, including the Databricks investigation, dual ransomware operations...
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used for downstream extortion and deployment after TeamPCP-sourced credential theft; described as part of a credential-to-extortion pipeline.
Ransomware whose operators leverage stolen credentials harvested via tampered open source software, allowing them to select victims from a pre-existing credential archive instead of conducting traditional reconnaissance or direct exploitation.
A ransomware-as-a-service operation that deploys ransomware and is collaborating with TeamPCP to turn stolen credentials from supply-chain compromises into ransomware attacks.
A ransomware-as-a-service operation whose latest version reportedly had a faulty encryption process that destroyed files larger than 128 KB, rendering them unrecoverable.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.