logo

Researchers Warn of New “Vect” RaaS Variant

ID: c1b29c59-fab1-5baa-9ac6-87658bbe4745

STIX ID: report--c1b29c59-fab1-5baa-9ac6-87658bbe4745

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2026-02-03

Date Updated: 2026-04-22

...
...

A new RaaS operation named Vect has been identified, claiming two victims in Brazil and South Africa and recruiting affiliates; it uses custom C++ ransomware employing ChaCha20-Poly1305 and intermittent block encryption, targets Windows/Linux/VMware ESXi, leverages Safe Mode evasion and strong OPSEC (Monero payments, TOX, TOR), and follows a double-extortion model. Analysts recommend hardening remote access (RDP/VPN/Fortinet), segmenting management networks, monitoring for Safe Mode and rapid selective encryption patterns, and deploying preventative anti-ransomware controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.