Vect is a ransomware-as-a-service operation that emerged in late 2025 and began claiming victims in early 2026. It provides affiliate-oriented ransomware and extortion infrastructure and has been associated with double-extortion activity, including data theft and publication of victim data. Vect has publicly partnered with TeamPCP, a financially motivated supply-chain and credential-theft actor; at least one Vect ransomware deployment has been verified using credentials sourced through TeamPCP activity.
Technical analysis of the Windows locker identified network-share and system enumeration, credential-enabled lateral-movement functions, service and process termination, Microsoft Defender and Task Manager disabling, shadow-copy deletion, and Safe Mode manipulation. It uses a libsodium ChaCha20-IETF-based file-encryption implementation and supports local and network-targeted encryption operations. The ransomware's large-file encryption routine contains a nonce-handling defect that preserves only one of several generated nonces, leaving portions of affected files unrecoverable even with the correct key. A separate buffer-handling flaw can cause some medium-sized files to be renamed without having their contents encrypted. These defects can make Vect incidents operationally resemble destructive wiper activity rather than reliable recoverable ransomware.
Vect has targeted enterprise Windows environments and has advertised Linux and VMware ESXi support, although available analysis found its Linux and ESXi builder functionality unreliable. Reported victim activity spans manufacturing, healthcare, education, information technology, and energy organizations. Its affiliate ecosystem has used anonymity-focused payment and communication mechanisms and leak-site publication to monetize intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VECERT reported on April 2, 2026 that the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The campaign’s harvested credentials were tied to the Vect ransomware operation, with affiliate access distributed through BreachForums in April 2026.”
The current pause, combined with the Vect ransomware affiliate announcement, suggests TeamPCP has shifted primary operational focus from supply chain expansion to monetization of existing credential harvests.
Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).
30 distinct techniques documented for this family, organized by ATT&CK tactic.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
TeamPCP compromised the telnyx Python SDK on PyPI, publishing malicious versions 4.87.1 and 4.87.2... the attacker used stolen PyPI credentials rather than a repository compromise.
Between March 19 and March 24, 2026, TeamPCP compromised the Trivy GitHub Actions workflow, the Checkmarx KICS package, the LiteLLM PyPI distribution (versions 1.82.7 and 1.82.8), and the Telnyx Python SDK. A credential-harvesting payload fired during CI/CD execution in downstream organizations.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
A double XOR routine intended to keep these flags encrypted at rest accidentally cancels itself out, leaving them as plaintext strings inside the binary.
Built-in LAN scanning enables automated network reconnaissance following initial access.
The Linux and ESXi variants implement CIS geofencing by reading LANG, LC_ALL, and /etc/timezone.
Impact Data Destruction T1485 Implementation defects can irreversibly corrupt files, producing a wiper-like effect regardless of intent.
the Vect ransomware affiliate announcement... no confirmed Vect deployments linked to TeamPCP credentials yet
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation whose affiliate program was reportedly provided access to credentials harvested in the TeamPCP supply-chain campaign.
Ransomware used for downstream extortion and deployment after TeamPCP-sourced credential theft; described as part of a credential-to-extortion pipeline.
Ransomware whose operators leverage stolen credentials harvested via tampered open source software, allowing them to select victims from a pre-existing credential archive instead of conducting traditional reconnaissance or direct exploitation.
A ransomware-as-a-service operation that partnered with TeamPCP to use stolen credentials from supply-chain compromises for ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.