New Vect 2.0 Ransomware Operation Expands Multi-Platform Attacks
ID: b01904c9-66c3-54a3-bd6b-cc61702aab8a
STIX ID: report--b01904c9-66c3-54a3-bd6b-cc61702aab8a
Feed Name: Cyber Press
The report describes the rise of Vect 2.0, a Ransomware-as-a-Service operation using a custom C++ codebase, TOR-hosted infrastructure, Monero payments and a triple-extortion model, with about 20 victims and an average attack-to-leak delay of eight days; it also highlights Starkiller, a commercial phishing/AitM framework that proxies real login pages via headless browsers to bypass MFA and capture session tokens, reducing the effectiveness of domain blocklisting and increasing initial access risk to organizations in manufacturing, education, healthcare and technology. Security guidance emphasizes identity-aware behavioral monitoring, session/token anomaly detection, and robust offline backups (3-2-1).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
