Vect is a financially motivated ransomware-as-a-service operation that emerged in late December 2025 and began claiming victims in early 2026. It operates as a double-extortion scheme, pairing file encryption with data theft and leak-site pressure, and later formed an operational partnership with TeamPCP to monetize credentials and access harvested through large-scale software supply-chain compromises. Public reporting indicates at least one verified Vect deployment using TeamPCP-sourced credentials, reflecting a credential-theft-to-ransomware pipeline rather than reliance solely on direct intrusion.
Vect is primarily associated with enterprise-focused attacks and supports Windows, Linux, and VMware ESXi environments. Its tooling has been described as purpose-built in C++ and linked against libsodium. Reported capabilities include disabling security controls, deleting shadow copies, terminating backup, database, and productivity processes, manipulating Safe Mode boot settings, and persisting to continue execution in Safe Mode. The malware also supports network and share enumeration and multiple lateral movement methods on Windows, including SMB, WinRM, WMI, DCOM, scheduled tasks, and remote service creation; supplied credentials can be used to facilitate propagation. Linux and ESXi support has been advertised, although some reporting indicates those builder paths were immature or unreliable during early analysis.
Vect has been promoted through underground affiliate channels and expanded unusually aggressively through partnerships with BreachForums and TeamPCP. The TeamPCP relationship is especially significant because TeamPCP compromised trusted developer and security tooling to steal CI/CD secrets, cloud credentials, package publishing tokens, SSH keys, and other non-human credentials at scale. Vect then appears to have used that upstream access and stolen data for downstream extortion and ransomware deployment. Victim claims span multiple regions and sectors, including technology, manufacturing, healthcare, education, finance, and energy.
Technical analysis of Vect 2.0 identified severe implementation flaws in its encryption logic. Although the malware uses ChaCha20-based intermittent encryption, nonce-handling defects mean many files larger than roughly 128 KB can become permanently unrecoverable, even if the operators possess the correct key. Additional file-handling bugs reportedly leave some mid-sized files renamed as encrypted without actually encrypting their contents. As a result, Vect incidents can behave operationally more like destructive wiper events than reliable ransomware, and ransom payment may not restore affected data. Defenders should therefore treat Vect compromises as both extortion and destructive-impact incidents.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VECERT reported on April 2, 2026 that the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Vect is a ransomware-as-a-service (RaaS) operation that began recruiting affiliates on Russian-language cybercrime forums in late December 2025 and started claiming victims in early January 2026.
The current pause, combined with the Vect ransomware affiliate announcement, suggests TeamPCP has shifted primary operational focus from supply chain expansion to monetization of existing credential harvests.
Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).
30 distinct techniques documented for this family, organized by ATT&CK tactic.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
TeamPCP compromised the telnyx Python SDK on PyPI, publishing malicious versions 4.87.1 and 4.87.2... the attacker used stolen PyPI credentials rather than a repository compromise.
Between March 19 and March 24, 2026, TeamPCP compromised the Trivy GitHub Actions workflow, the Checkmarx KICS package, the LiteLLM PyPI distribution (versions 1.82.7 and 1.82.8), and the Telnyx Python SDK. A credential-harvesting payload fired during CI/CD execution in downstream organizations.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
A double XOR routine intended to keep these flags encrypted at rest accidentally cancels itself out, leaving them as plaintext strings inside the binary.
Built-in LAN scanning enables automated network reconnaissance following initial access.
The Linux and ESXi variants implement CIS geofencing by reading LANG, LC_ALL, and /etc/timezone.
Impact Data Destruction T1485 Implementation defects can irreversibly corrupt files, producing a wiper-like effect regardless of intent.
the Vect ransomware affiliate announcement... no confirmed Vect deployments linked to TeamPCP credentials yet
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used for downstream extortion and deployment after TeamPCP-sourced credential theft; described as part of a credential-to-extortion pipeline.
Ransomware whose operators leverage stolen credentials harvested via tampered open source software, allowing them to select victims from a pre-existing credential archive instead of conducting traditional reconnaissance or direct exploitation.
A ransomware-as-a-service operation that deploys ransomware and is collaborating with TeamPCP to turn stolen credentials from supply-chain compromises into ransomware attacks.
A ransomware-as-a-service operation whose latest version reportedly had a faulty encryption process that destroyed files larger than 128 KB, rendering them unrecoverable.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.