Vect is a financially motivated ransomware-as-a-service operation that emerged in late December 2025 and began active victim targeting in early 2026. It is positioned as a double-extortion enterprise ransomware family, with operators and affiliates using stolen data for coercion in addition to file encryption. Vect has been associated with a formal partnership with TeamPCP, in which TeamPCP’s large-scale software supply-chain compromises and credential theft operations provided downstream access that could later be monetized through Vect ransomware deployments. At least one Vect deployment has been reported as using TeamPCP-sourced credentials.
Vect is a cross-platform C++ ransomware family targeting Windows, Linux, and VMware ESXi environments. Reported capabilities include LAN scanning, credential-assisted propagation, and lateral movement through SMB, WinRM, remote service creation, scheduled-task execution, and SSH on non-Windows systems. The malware is also described as terminating security, backup, database, and productivity processes, deleting shadow copies and backup catalogs, and manipulating Safe Mode boot settings to weaken defenses and inhibit recovery before encryption. Vect is operated through Tor-based extortion infrastructure with affiliate-oriented management features and a structured revenue-sharing model.
Technical analysis of Vect 2.0 identified a severe cryptographic implementation flaw affecting Windows, Linux, and ESXi variants. Large files are processed in chunks, but nonce-handling defects cause required values for earlier chunks to be lost, making many encrypted files permanently unrecoverable even by the operators. As a result, incidents involving Vect can behave operationally like destructive wiper events rather than recoverable ransomware cases. This flaw has been reported across multiple variants and materially undermines the reliability of ransom-based recovery.
Vect has been linked to broad affiliate recruitment and low-friction onboarding, including mass distribution of affiliate access through criminal forums. Public reporting also notes possible overlaps with Devman based on code and operational similarities, but that relationship is not conclusively established. Organizations exposed to TeamPCP-compromised CI/CD and software supply-chain environments are at elevated risk of downstream Vect extortion or ransomware activity because stolen credentials, cloud secrets, and automation tokens can be reused long after the initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VECERT reported on April 2, 2026 that the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Vect ransomware group has begun publishing victim data obtained from the March 2026 TeamPCP Trivy supply chain compromise, confirming that a campaign affecting more than 1,000 enterprise software-as-a-service (SaaS) environments has escalated from credential theft and espionage into active double-extortion ransomware operations.
Update 002 covered developments through March 27, including the Telnyx PyPI compromise and Vect ransomware partnership.
Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).
30 distinct techniques documented for this family, organized by ATT&CK tactic.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
Between February and March 2026, TeamPCP tampered with four widely used open source packages that development teams rely on daily.
Between March 19 and March 24, 2026, TeamPCP compromised the Trivy GitHub Actions workflow, the Checkmarx KICS package, the LiteLLM PyPI distribution (versions 1.82.7 and 1.82.8), and the Telnyx Python SDK. A credential-harvesting payload fired during CI/CD execution in downstream organizations.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
A double XOR routine intended to keep these flags encrypted at rest accidentally cancels itself out, leaving them as plaintext strings inside the binary.
Built-in LAN scanning enables automated network reconnaissance following initial access.
The Linux and ESXi variants implement CIS geofencing by reading LANG, LC_ALL, and /etc/timezone.
Impact Data Destruction T1485 Implementation defects can irreversibly corrupt files, producing a wiper-like effect regardless of intent.
the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
The locker then terminates a hardcoded list of security agents ... backup engines ... database services
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used for downstream extortion and deployment after TeamPCP-sourced credential theft; described as part of a credential-to-extortion pipeline.
Ransomware whose operators leverage stolen credentials harvested via tampered open source software, allowing them to select victims from a pre-existing credential archive instead of conducting traditional reconnaissance or direct exploitation.
A ransomware-as-a-service operation that deploys ransomware and is collaborating with TeamPCP to turn stolen credentials from supply-chain compromises into ransomware attacks.
A ransomware-as-a-service operation whose latest version reportedly had a faulty encryption process that destroyed files larger than 128 KB, rendering them unrecoverable.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.