Vect, also known as VECT operators and the Vect ransomware group, is a Russian-speaking ransomware-as-a-service operation first observed in late 2025. It recruits affiliates and provides ransomware deployment and extortion infrastructure, including a leak site, while retaining a substantial share of affiliate proceeds. Vect entered a formal operational partnership with the financially motivated supply-chain actor TeamPCP in late March 2026. In that division of labor, TeamPCP supplies access and stolen data obtained through compromises of developer tooling and CI/CD environments, while Vect conducts ransomware deployment and extortion. At least one Vect ransomware deployment using TeamPCP-sourced credentials has been verified. Vect has employed double extortion, combining data theft and threatened publication with file encryption. Its tooling targets Windows environments and includes network discovery and propagation capabilities through Windows administration mechanisms, SMB, and remote management services. It can inhibit defenses and recovery by disabling security controls, terminating backup, database, and productivity processes, deleting shadow copies, and altering Safe Mode settings. Analysis of Vect 2.0 identified serious implementation defects in its encryption routines that can leave victims unable to recover some files even with the correct decryption material; Vect incidents therefore carry destructive as well as extortion risk. Before the TeamPCP partnership, Vect claimed victims in Brazil, India, South Africa, and the United States, including organizations in manufacturing, health care, information technology, and energy. The group uses affiliate-driven operations and has integrated recruitment activity with cybercrime forums.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group partnered with TeamPCP to monetize stolen data and publish victims using access/data obtained by TeamPCP.
Ransomware and extortion actor associated with deploying ransomware using TeamPCP-sourced credentials and monetizing downstream access through extortion infrastructure.
Ransomware operators using TeamPCP-harvested stolen credentials from compromised software supply chains to gain initial access and select victims from a prebuilt credential archive rather than conducting their own reconnaissance.
Ransomware-as-a-service operation partnering with TeamPCP to use stolen credentials from supply chain compromises for ransomware deployment, representing an industrialized ransomware model.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.