VECT 2.0 Ransomware Wipes Large Files Across Windows, Linux & ESXi
ID: 1fab6b94-080c-5f41-9717-a1f29103c120
STIX ID: report--1fab6b94-080c-5f41-9717-a1f29103c120
Feed Name: GBHackers
Check Point Research's analysis reveals VECT 2.0 is a cross-platform ransomware-as-a-service that effectively acts as a destructive wiper: for files larger than 128 KB it encrypts four 32 KB chunks using ChaCha20‑IETF but only writes the final 12‑byte nonce to disk, making three quarters of affected large files mathematically unrecoverable; the report describes the flawed encryption implementation, lack of authentication, multi-platform samples (Windows, Linux, ESXi), RaaS distribution ties (including BreachForums and TeamPCP), and recommends treating infections as data‑wiping incidents and prioritizing offline backups and early detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
