logo

Don't pay Vect a ransom - your data's likely already wiped out

ID: 354ef31a-33e5-5011-924d-4707d912b2dc

STIX ID: report--354ef31a-33e5-5011-924d-4707d912b2dc

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Jessica Lyons

...
...

Check Point Research analyzed malware used by the Vect ransomware-as-a-service group (partnered with TeamPCP) and found that the tool is effectively a wiper: it permanently destroys any file larger than 128 KB across Windows, Linux, and ESXi variants due to nonce-handling and other implementation flaws, making recovery impossible. The report describes Vect and TeamPCP's supply-chain compromises (targeting tools like Trivy and LiteLLM), their use of credential-stealing malware for initial access, the groups' extortion and leak site activity (25 victims listed), and notes the low technical quality of the malware despite malicious intent.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.