Vect is a financially motivated ransomware-as-a-service operation and ransomware family that emerged in late 2025 and began claiming victims in early 2026. It operates a double-extortion model in which affiliates encrypt victim systems and threaten publication of stolen data through Tor-based extortion infrastructure. Vect has been publicly associated with a large-scale criminal collaboration with TeamPCP, in which TeamPCP’s software supply-chain compromises and credential theft provided downstream access later used for Vect ransomware deployment. At least one verified Vect deployment has been reported using TeamPCP-sourced credentials, indicating that the access-to-extortion pipeline was operational rather than merely advertised.
Vect is implemented in C++ and has been reported to target Windows, Linux, and VMware ESXi environments. Its Windows locker includes enterprise-focused functionality such as disabling security controls, deleting shadow copies, terminating backup, database, and productivity processes, manipulating Safe Mode boot settings, and persisting to continue execution in Safe Mode. It also supports multiple lateral movement mechanisms and can use supplied credentials to spread across networked systems and administrative channels. Reported capabilities include network share enumeration, remote task or service execution, and propagation through common Windows administration mechanisms; Linux and ESXi support has also been advertised and observed in builder functionality, although some analyses found those builds immature or unreliable.
A notable characteristic of Vect is that its encryption implementation is seriously flawed. Multiple analyses concluded that defects in nonce handling and file-processing logic can leave many files, especially larger ones, permanently unrecoverable even if the correct key is available. As a result, Vect incidents can behave operationally more like destructive wiper events than recoverable ransomware cases. This destructive outcome is generally assessed as poor implementation rather than deliberate wiper design, but the practical impact on victims is the same: ransom payment may not restore data.
Vect’s criminal ecosystem has included affiliate recruitment on Russian-language forums, low-cost affiliate onboarding, Monero-based payments, and integration with underground forum communities. Reporting has also noted possible overlaps with Devman in code strings and operational conventions, but available evidence is insufficient to treat that relationship as confirmed lineage. Victim claims have spanned multiple sectors including technology, manufacturing, healthcare, education, finance, and energy, with activity reported across several regions. Organizations exposed to TeamPCP-linked CI/CD and software supply-chain compromises face elevated risk of subsequent Vect ransomware deployment because stolen credentials, tokens, and secrets can be monetized long after the initial intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VECERT reported on April 2, 2026 that the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the collaboration is between the Vect ransomware group and TeamPCP
The current pause, combined with the Vect ransomware affiliate announcement, suggests TeamPCP has shifted primary operational focus from supply chain expansion to monetization of existing credential harvests.
Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).
30 distinct techniques documented for this family, organized by ATT&CK tactic.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
TeamPCP compromised the telnyx Python SDK on PyPI, publishing malicious versions 4.87.1 and 4.87.2... the attacker used stolen PyPI credentials rather than a repository compromise.
Between March 19 and March 24, 2026, TeamPCP compromised the Trivy GitHub Actions workflow, the Checkmarx KICS package, the LiteLLM PyPI distribution (versions 1.82.7 and 1.82.8), and the Telnyx Python SDK. A credential-harvesting payload fired during CI/CD execution in downstream organizations.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
A double XOR routine intended to keep these flags encrypted at rest accidentally cancels itself out, leaving them as plaintext strings inside the binary.
Built-in LAN scanning enables automated network reconnaissance following initial access.
The Linux and ESXi variants implement CIS geofencing by reading LANG, LC_ALL, and /etc/timezone.
Impact Data Destruction T1485 Implementation defects can irreversibly corrupt files, producing a wiper-like effect regardless of intent.
the Vect ransomware affiliate announcement... no confirmed Vect deployments linked to TeamPCP credentials yet
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware used for downstream extortion and deployment after TeamPCP-sourced credential theft; described as part of a credential-to-extortion pipeline.
Ransomware whose operators leverage stolen credentials harvested via tampered open source software, allowing them to select victims from a pre-existing credential archive instead of conducting traditional reconnaissance or direct exploitation.
A ransomware-as-a-service operation that partnered with TeamPCP to use stolen credentials from supply-chain compromises for ransomware deployment.
A ransomware-as-a-service operation that deploys ransomware and is collaborating with TeamPCP to turn stolen credentials from supply-chain compromises into ransomware attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.