logo

Inside Vect Ransomware-as-a-Service

ID: 32c7d622-5672-51fa-8886-d76922caa606

STIX ID: report--32c7d622-5672-51fa-8886-d76922caa606

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: SpiderLabs Researcher

...
...

Vect is an emerging, multi-platform RaaS active since January 2026 that leverages partnerships with TeamPCP and BreachForums to rapidly expand an affiliate base; it provides Windows, Linux and ESXi payload builders, implements robust lateral movement (RDP/SMB/WinRM/PSExec/Scheduled Tasks), uses ChaCha20 encryption and VM termination for maximum impact, includes geo-fencing to exclude CIS/post‑Soviet regions, and has publicly posted victims and file-hash IOCs, indicating an active high-risk criminal campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.