Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
ID: d5c3b06d-2a25-5a24-8511-7a9ad43932f6
STIX ID: report--d5c3b06d-2a25-5a24-8511-7a9ad43932f6
Feed Name: Dark Reading
Check Point and other researchers found that the Vect 2.0 ransomware contains a critical implementation flaw: it generates four nonces per large file chunk but only stores the final nonce, rendering the first three chunks undecryptable and effectively turning the ransomware into a wiper for files >=128 KB across Windows, Linux, and ESXi. The flaw, combined with Vect's active RaaS operation and partnership with TeamPCP (a supply-chain actor), makes it a destructive threat to organizations with critical data; defenders are advised to prioritize prevention, enforce strict access controls, isolate virtualization management, and maintain offline immutable backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
