PULSE NAME
VECT: Ransomware by design, Wiper by accident
WHITE VECT AlienVault 2026-04-28 Modified: 2026-04-29
16
IOCs
MEDIUM VOLUME
Check Point Research discovered critical flaws in VECT 2.0 ransomware affecting Windows, Linux, and ESXi platforms. A fundamental encryption implementation error causes files larger than 128 KB to be permanently destroyed rather than encrypted. The malware uses ChaCha20-IETF cipher but only saves one of four decryption nonces required for large files, making recovery impossible even after ransom payment. VECT's encryption speed modes are non-functional, thread scheduling degrades performance, and anti-analysis code is unreachable. Despite partnerships with TeamPCP and BreachForums for distribution, the technical implementation demonstrates amateur execution behind a professional facade. The nonce-handling flaw exists across all platform variants since initial deployment, effectively transforming this ransomware into a wiper for enterprise assets including VM disks, databases, and backups.
Indicators of Compromise (4 / 16 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 e27f4feffc1ba6bf4e35aec4a5270fccb636e5cf 2026-04-28
FileHash-SHA1 ecba8e27fe57953fa43818f141cee17db4ba6a07 2026-04-28
FileHash-SHA1 f4b904fb6ba8474cb87f26302b74c4b82c106003 2026-04-28
FileHash-SHA1 fe65bd9073617752460ac3419881c67848381fa3 2026-04-28