Vect is an emerging ransomware-as-a-service operation that appeared in late 2025 and expanded in early 2026 through affiliate recruitment on Russian-language cybercrime forums and partnerships with BreachForums and TeamPCP. The group is best known for combining ransomware deployment and extortion infrastructure with access and stolen data sourced from TeamPCP’s large-scale software supply-chain and credential-theft operations, creating a pipeline from poisoned developer tooling to downstream ransomware monetization. Vect operates as a RaaS program and has been described as Russian-speaking. It offered unusually broad affiliate onboarding, including mass distribution of affiliate keys and high profit shares for affiliates. Public reporting indicates the group used a double-extortion model, publishing victim data on a leak site and pairing data theft with ransomware deployment. At least one verified Vect ransomware deployment has been linked to credentials harvested by TeamPCP, indicating the partnership was operational rather than merely promotional. Vect publicly aligned itself with organizations compromised through the Trivy and LiteLLM supply-chain incidents and stated intent to pursue ransomware operations against affected organizations. Earlier victim claims were concentrated in Brazil, the United States, South Africa, and India, with targeting reported across manufacturing, healthcare, education, information technology, and energy. Additional named victim claims tied to TeamPCP-derived access have included organizations in property technology and financial information services, though not all public claims are independently confirmed. Technical analysis of Vect 2.0 shows a custom ransomware family with Windows-focused functionality and attempted support for Linux and ESXi. Observed capabilities include data theft extortion, encryption, defense evasion, persistence, reconnaissance, and lateral movement. The malware disables security controls, deletes shadow copies, manipulates Safe Mode boot settings, terminates backup, database, security, and productivity processes, enumerates network shares, accepts supplied Active Directory credentials, and spreads through administrative mechanisms including WinRM, WMI, DCOM, scheduled tasks, services, and group-policy-based deployment. It uses intermittent encryption for larger files and full encryption for smaller files. Multiple reverse-engineering reports identified severe implementation flaws in Vect’s locker. In particular, nonce-handling defects in large-file encryption can render files permanently unrecoverable, and buffer-management bugs can leave some files renamed without being properly encrypted. As a result, Vect has been assessed as behaving in some cases more like a destructive wiper than a reliable extortion tool, and victims cannot assume payment would enable restoration. Known aliases include VECT, VECT operators, Vect ransomware, and Vect ransomware group. Vect is closely associated with TeamPCP in 2026 reporting, where TeamPCP supplied initial access, stolen credentials, and exfiltrated data while Vect provided ransomware deployment and extortion tooling. The actor’s dominant motivation is financial.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
27 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group partnered with TeamPCP to monetize stolen data and publish victims using access/data obtained by TeamPCP.
Ransomware and extortion actor associated with deploying ransomware using TeamPCP-sourced credentials and monetizing downstream access through extortion infrastructure.
Ransomware operators using TeamPCP-harvested stolen credentials from compromised software supply chains to gain initial access and select victims from a prebuilt credential archive rather than conducting their own reconnaissance.
Ransomware-as-a-service operation partnering with TeamPCP to use stolen credentials from supply chain compromises for ransomware deployment, representing an industrialized ransomware model.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.