logo

New Vect 2.0 Ransomware Operation Expands Multi-Platform Attacks

ID: b01904c9-66c3-54a3-bd6b-cc61702aab8a

STIX ID: report--b01904c9-66c3-54a3-bd6b-cc61702aab8a

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Varshini

...
...

The report describes the rise of Vect 2.0, a Ransomware-as-a-Service operation using a custom C++ codebase, TOR-hosted infrastructure, Monero payments and a triple-extortion model, with about 20 victims and an average attack-to-leak delay of eight days; it also highlights Starkiller, a commercial phishing/AitM framework that proxies real login pages via headless browsers to bypass MFA and capture session tokens, reducing the effectiveness of domain blocklisting and increasing initial access risk to organizations in manufacturing, education, healthcare and technology. Security guidance emphasizes identity-aware behavioral monitoring, session/token anomaly detection, and robust offline backups (3-2-1).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.