← Back to Pulse Feed
PULSE DETAIL
Check Point Research discovered critical flaws in VECT 2.0 ransomware affecting Windows, Linux, and ESXi platforms. A fundamental encryption implementation error causes files larger than 128 KB to be permanently destroyed rather than encrypted. The malware uses ChaCha20-IETF cipher but only saves one of four decryption nonces required for large files, making recovery impossible even after ransom payment. VECT's encryption speed modes are non-functional, thread scheduling degrades performance, and anti-analysis code is unreachable. Despite partnerships with TeamPCP and BreachForums for distribution, the technical implementation demonstrates amateur execution behind a professional facade. The nonce-handling flaw exists across all platform variants since initial deployment, effectively transforming this ransomware into a wiper for enterprise assets including VM disks, databases, and backups.
MITRE ATT&CK & Malware Families
Indicators of Compromise (4 / 16 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA1 | e27f4feffc1ba6bf4e35aec4a5270fccb636e5cf | — | 2026-04-28 | |
| FileHash-SHA1 | ecba8e27fe57953fa43818f141cee17db4ba6a07 | — | 2026-04-28 | |
| FileHash-SHA1 | f4b904fb6ba8474cb87f26302b74c4b82c106003 | — | 2026-04-28 | |
| FileHash-SHA1 | fe65bd9073617752460ac3419881c67848381fa3 | — | 2026-04-28 |