Vect is a financially motivated, Russian-speaking ransomware-as-a-service operation that emerged in late December 2025 and rapidly expanded through aggressive affiliate recruitment and double-extortion operations. It is commonly referred to as Vect, VECT, Vect ransomware, or Vect operators. The group advertises a multi-platform locker for Windows, Linux, and VMware ESXi environments and operates leak-site infrastructure to pressure victims through data publication in addition to encryption. Vect is notable for combining conventional ransomware tradecraft with unusually broad criminal ecosystem partnerships. In 2026 it formalized relationships with BreachForums and with TeamPCP, creating a pipeline in which TeamPCP’s software supply-chain compromises and credential theft supplied downstream access that Vect and its affiliates could monetize through extortion and ransomware deployment. Public reporting links this partnership to victim data publication and at least one confirmed ransomware deployment using TeamPCP-sourced credentials. Vect has also been described as functioning within a wider access-broker and affiliate ecosystem, with some reporting noting overlap or cooperation with actors such as CipherForce. Operationally, Vect follows a double-extortion model: affiliates obtain or receive access, steal data, deploy the locker, and threaten publication if payment is not made. The operation has targeted organizations across multiple regions and sectors, including technology, financial services, healthcare, manufacturing, education, energy, and other enterprise environments. Reporting indicates that some victims were selected from organizations exposed through major 2026 supply-chain compromises affecting developer and security tooling embedded in CI/CD workflows. Vect’s malware and operator tradecraft support lateral movement and enterprise-wide impact. Reported capabilities include propagation through SMB, WinRM, remote service creation, scheduled-task execution, WMI/DCOM-style remote execution, and SSH in Linux or ESXi environments. The locker is also reported to disable or interfere with security controls, terminate security, backup, database, and productivity processes, delete shadow copies, and manipulate Safe Mode boot settings to improve execution reliability. Affiliates reportedly communicate through underground channels and use Monero-centric payment workflows. A significant characteristic of Vect is that multiple researchers reported a serious implementation flaw in its encryption routine. Large files may be permanently corrupted rather than recoverably encrypted, making some incidents operationally closer to destructive wiper activity than traditional ransomware. As a result, victims cannot assume that payment will enable restoration even if the operators cooperate. Vect is assessed as a cybercriminal rather than state-sponsored actor. Its Russian-language recruitment, CIS-focused affiliate incentives, and underground forum presence are consistent with a Russian-speaking operational base. Some technical and operational overlaps with Devman have been reported, including similarities in builder strings, ransom-note style, and lateral-movement naming conventions, but any definitive relationship remains unconfirmed. Overall, Vect represents an emerging ransomware brand distinguished by rapid affiliate scaling, integration with criminal marketplaces, and its role in monetizing access generated through large-scale software supply-chain and credential-theft campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware and extortion actor associated with deploying ransomware using TeamPCP-sourced credentials and monetizing downstream access through extortion infrastructure.
Ransomware operators using TeamPCP-harvested stolen credentials from compromised software supply chains to gain initial access and select victims from a prebuilt credential archive rather than conducting their own reconnaissance.
Ransomware-as-a-service operator collaborating with TeamPCP to combine credential harvesting and stolen data from supply chain compromises with Vect's ransomware deployment infrastructure.
Ransomware-as-a-service operation partnering with TeamPCP to deploy ransomware against organizations compromised through supply chain attacks and stolen credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.