New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi
ID: 1f7b21ed-8341-5125-8236-b0eca8e90f16
STIX ID: report--1f7b21ed-8341-5125-8236-b0eca8e90f16
Feed Name: cybersecurityNews.com
VECT 2.0 is a cross-platform RaaS ransomware that, due to a critical nonce-handling bug, permanently renders any file over 128 KB unrecoverable; the gang expanded distribution via partnerships (TeamPCP, BreachForums) and targets Windows, Linux, and VMware ESXi. The report details the technical flaw (per-chunk nonces overwritten so only the final nonce is stored), operational indicators (.vect extension, !!!READ_ME!!!.txt ransom notes, PowerShell-based Defender disabling), and recommends offline backups, monitoring for mass file renames/deletions, and validating third-party dependencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
