Critical Flaw Turns Vect Ransomware into Data Destroying Wiper
ID: b2b167ec-c6fb-5f65-b9ee-f9b2c367a36a
STIX ID: report--b2b167ec-c6fb-5f65-b9ee-f9b2c367a36a
Feed Name: Infosecurity Magazine (News)
Check Point Research analysed Vect 2.0 RaaS and found a critical cryptographic implementation flaw—the malware uses raw ChaCha20 without Poly1305 and mishandles nonces—causing files larger than 128 KB (including VM disks, databases, documents and backups) to be permanently destroyed rather than recoverably encrypted; Vect targets Windows, Linux and VMware ESXi, is distributed via an active affiliate program and partnerships (including TeamPCP and BreachForums), and therefore presents a high-impact, multi-platform destructive threat despite poor technical implementation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
