Inside Vect Ransomware-as-a-Service
ID: 32c7d622-5672-51fa-8886-d76922caa606
STIX ID: report--32c7d622-5672-51fa-8886-d76922caa606
Feed Name: LevelBlue SpiderLabs Blog
Vect is an emerging, multi-platform RaaS active since January 2026 that leverages partnerships with TeamPCP and BreachForums to rapidly expand an affiliate base; it provides Windows, Linux and ESXi payload builders, implements robust lateral movement (RDP/SMB/WinRM/PSExec/Scheduled Tasks), uses ChaCha20 encryption and VM termination for maximum impact, includes geo-fencing to exclude CIS/post‑Soviet regions, and has publicly posted victims and file-hash IOCs, indicating an active high-risk criminal campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
