logo

VECT: Ransomware by design, Wiper by accident

ID: 8ee80ce2-6093-5807-93fe-9e26b9ace7e3

STIX ID: report--8ee80ce2-6093-5807-93fe-9e26b9ace7e3

Feed Name: Check Point Research

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: [email protected]

...
...

**Executive summary:** Check Point Research analyzed VECT 2.0, a Ransomware-as-a-Service targeting Windows, Linux, and ESXi, and found a critical cross-platform nonce-handling flaw in its ChaCha20-IETF encryption that discards three of four per-chunk nonces for files >128 KB—rendering large files permanently unrecoverable and effectively turning the ransomware into a destructive wiper; the report also documents operational details (affiliate program, TeamPCP supply-chain ties), IOCs, lateral-movement and anti-analysis behaviors, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.