PULSE NAME
VECT: Ransomware by design, Wiper by accident
WHITE VECT AlienVault 2026-04-28 Modified: 2026-04-29
16
IOCs
MEDIUM VOLUME
Check Point Research discovered critical flaws in VECT 2.0 ransomware affecting Windows, Linux, and ESXi platforms. A fundamental encryption implementation error causes files larger than 128 KB to be permanently destroyed rather than encrypted. The malware uses ChaCha20-IETF cipher but only saves one of four decryption nonces required for large files, making recovery impossible even after ransom payment. VECT's encryption speed modes are non-functional, thread scheduling degrades performance, and anti-analysis code is unreachable. Despite partnerships with TeamPCP and BreachForums for distribution, the technical implementation demonstrates amateur execution behind a professional facade. The nonce-handling flaw exists across all platform variants since initial deployment, effectively transforming this ransomware into a wiper for enterprise assets including VM disks, databases, and backups.
Indicators of Compromise (16)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 207b1a60f803d348c795d382f5aed9c3 2026-04-28
FileHash-MD5 4cc6e614e0b766ced936a7e44976f10a 2026-04-28
FileHash-MD5 7f6670a37338ffcaa61578e24164c540 2026-04-28
FileHash-MD5 aa72609186042f1d7d01ce070306a9f2 2026-04-28
FileHash-SHA1 e27f4feffc1ba6bf4e35aec4a5270fccb636e5cf 2026-04-28
FileHash-SHA1 ecba8e27fe57953fa43818f141cee17db4ba6a07 2026-04-28
FileHash-SHA1 f4b904fb6ba8474cb87f26302b74c4b82c106003 2026-04-28
FileHash-SHA1 fe65bd9073617752460ac3419881c67848381fa3 2026-04-28
FileHash-SHA256 58e17dd61d4d55fa77c7f2dd28dd51875b0ce900c1e43b368b349e65f27d6fdd 2026-04-28
FileHash-SHA256 8ee4ec425bc0d8db050d13bbff98f483fff020050d49f40c5055ca2b9f6b1c4d 2026-04-28
FileHash-SHA256 9c745f95a09b37bc0486bf0f92aad4a3d5548a939c086b93d6235d34648e683f 2026-04-28
FileHash-SHA256 a7eadcf81dd6fda0dd6affefaffcb33b1d8f64ddec6e5a1772d028ef2a7da0f2 2026-04-28
FileHash-SHA256 e1fc59c7ece6e9a7fb262fc8529e3c4905503a1ca44630f9724b2ccc518d0c06 2026-04-28
FileHash-SHA256 e512d22d2bd989f35ebaccb63615434870dc0642b0f60e6d4bda0bb89adee27a 2026-04-28
URL http://vectordntlcrlmfkcm4alni734tbcrnd5lk44v6sp4lqal6noqrgnbyd.onion/chat/REDACTED 2026-04-28
domain vectordntlcrlmfkcm4alni734tbcrnd5lk44v6sp4lqal6noqrgnbyd.onion 2026-04-28