Researchers Warn of New “Vect” RaaS Variant
ID: c1b29c59-fab1-5baa-9ac6-87658bbe4745
STIX ID: report--c1b29c59-fab1-5baa-9ac6-87658bbe4745
Feed Name: Infosecurity Magazine (News)
A new RaaS operation named Vect has been identified, claiming two victims in Brazil and South Africa and recruiting affiliates; it uses custom C++ ransomware employing ChaCha20-Poly1305 and intermittent block encryption, targets Windows/Linux/VMware ESXi, leverages Safe Mode evasion and strong OPSEC (Monero payments, TOX, TOR), and follows a double-extortion model. Analysts recommend hardening remote access (RDP/VPN/Fortinet), segmenting management networks, monitoring for Safe Mode and rapid selective encryption patterns, and deploying preventative anti-ransomware controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
