Vect is a financially motivated, Russian-speaking ransomware-as-a-service operation that emerged in late 2025 and expanded rapidly in early 2026 through aggressive affiliate recruitment and partnerships with BreachForums and TeamPCP. The group operates a double-extortion model in which data theft is paired with encryption and leak-site pressure, and it has been linked to downstream monetization of access and data harvested during TeamPCP’s large-scale software supply-chain compromises affecting Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK. Reporting indicates at least one verified Vect ransomware deployment using TeamPCP-sourced credentials, demonstrating an operational pipeline from supply-chain compromise and credential theft to extortion and ransomware deployment. Vect advertises high affiliate revenue shares and broadly distributed affiliate keys, lowering barriers to entry for ransomware activity. The operation has targeted organizations across multiple regions, with victim reporting concentrated in the United States, Brazil, South Africa, and India, and sectors including manufacturing, healthcare, education, information technology, energy, and financial services. Publicly reported victim claims tied to TeamPCP-derived access also include organizations affected through enterprise SaaS and software-development environments. Technically, Vect supports Windows and claims Linux and VMware ESXi targeting, and its tooling includes defense evasion, persistence, credential-assisted lateral movement, network share access, service and scheduled-task based propagation, Safe Mode abuse, and shadow-copy deletion. Observed behavior includes disabling security controls, terminating backup and database-related processes, mounting or traversing network shares, and using administrative mechanisms such as WinRM, WMI, DCOM, scheduled tasks, and remote services for spread. The malware uses ChaCha20-based intermittent encryption and appends a custom extension to impacted files. Multiple analyses have identified severe implementation flaws in Vect’s encryption logic. Large-file handling contains nonce-management defects that can make encrypted data unrecoverable even with the correct key, and additional buffer-handling bugs can leave some files renamed without being properly encrypted. As a result, Vect incidents may behave partly as destructive wiper events rather than reliably recoverable ransomware operations. Researchers have also noted overlaps with Devman-style conventions, but those similarities do not by themselves establish lineage. Known aliases and naming variants include VECT, VECT 2.0, Vect operators, and Vect ransomware group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group partnered with TeamPCP to monetize stolen data and publish victims using access/data obtained by TeamPCP.
Ransomware and extortion actor associated with deploying ransomware using TeamPCP-sourced credentials and monetizing downstream access through extortion infrastructure.
Ransomware operators using TeamPCP-harvested stolen credentials from compromised software supply chains to gain initial access and select victims from a prebuilt credential archive rather than conducting their own reconnaissance.
Ransomware-as-a-service operator collaborating with TeamPCP to combine credential harvesting and stolen data from supply chain compromises with Vect's ransomware deployment infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.