Vect is a ransomware family distributed through a ransomware-as-a-service operation that emerged in late December 2025 and began claiming victims in January 2026. Its affiliate model combines file encryption with extortion and publication of victim data. The operation has targeted organizations across manufacturing, healthcare, education, information technology, and energy, with early victim claims spanning several countries.
The analyzed Windows locker uses libsodium’s ChaCha20-IETF cipher. It terminates security, backup, database, and productivity processes, disables Microsoft Defender protections and Task Manager, and deletes volume shadow copies to inhibit recovery. It supports Safe Mode execution and persistence, network-share enumeration, and credential-assisted lateral movement through Windows remote administration mechanisms, including WinRM, WMI, DCOM, scheduled tasks, and services.
Vect 2.0 contains serious encryption implementation defects. For files larger than 128 KB, it encrypts four separate regions using different nonces but preserves only the final nonce, leaving the earlier encrypted regions unrecoverable even with the correct key. A separate buffer-handling defect can leave some smaller files unencrypted despite modifying their metadata. These flaws make affected deployments potentially destructive rather than reliably reversible ransomware; ransom payment does not guarantee recovery.
In late March 2026, Vect announced an operational partnership with TeamPCP, also tracked as UNC6780, combining TeamPCP’s software-supply-chain credential harvesting and data theft with Vect’s ransomware infrastructure. At least one verified Vect deployment used TeamPCP-sourced credentials. The relationship enables downstream ransomware attacks against organizations whose developer, cloud, or automation credentials were exposed through compromised tooling, including Trivy and LiteLLM. Vect also partnered with BreachForums to recruit affiliates and distribute access to its ransomware platform. TeamPCP’s credential-stealing payloads are distinct from the Vect locker.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VECERT reported on April 2, 2026 that the Sportradar AG breach ... has been confirmed as a "systemic compromise" jointly operated by TeamPCP and Vect ransomware.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The article describes downstream extortion by "groups like Vect ransomware (TeamPCP)" and identifies Guesty and S&P Global on Vect's leak site.
The current pause, combined with the Vect ransomware affiliate announcement, suggests TeamPCP has shifted primary operational focus from supply chain expansion to monetization of existing credential harvests.
Check Point researchers opened a BreachForums account, got access to the panel and ransomware builder, and analyzed the gang's malware. They quickly determined that the ransomware-as-a-service group also isn't very good at writing code ... and they appear to have accidentally written a data wiper. Instead of encrypting large files ... Vect 2.0 ransomware permanently destroys any files larger than 131,072 bytes (128 KB).
30 distinct techniques documented for this family, organized by ATT&CK tactic.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
TeamPCP compromised the telnyx Python SDK on PyPI, publishing malicious versions 4.87.1 and 4.87.2... the attacker used stolen PyPI credentials rather than a repository compromise.
Between March 19 and March 24, 2026, TeamPCP compromised the Trivy GitHub Actions workflow, the Checkmarx KICS package, the LiteLLM PyPI distribution (versions 1.82.7 and 1.82.8), and the Telnyx Python SDK. A credential-harvesting payload fired during CI/CD execution in downstream organizations.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
VECT’s operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses.
The function labeled “GPO spread” performs no Group Policy operations. It registers Scheduled Tasks remotely over CIM sessions, each named with a hardcoded “DM” prefix followed by four random uppercase letters.
A double XOR routine intended to keep these flags encrypted at rest accidentally cancels itself out, leaving them as plaintext strings inside the binary.
Built-in LAN scanning enables automated network reconnaissance following initial access.
The Linux and ESXi variants implement CIS geofencing by reading LANG, LC_ALL, and /etc/timezone.
Impact Data Destruction T1485 Implementation defects can irreversibly corrupt files, producing a wiper-like effect regardless of intent.
the Vect ransomware affiliate announcement... no confirmed Vect deployments linked to TeamPCP credentials yet
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
51 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation that reportedly received credentials from TeamPCP for use in attacks.
Ransomware operation whose affiliate program was reportedly provided access to credentials harvested in the TeamPCP supply-chain campaign.
Named ransomware associated with downstream data theft and extortion following the supply-chain campaign. The article reports claims of 700 GB stolen from Guesty and 250 GB from S&P Global, but does not describe the ransomware's implementation or establish that files were encrypted.
Ransomware used for downstream extortion and deployment after TeamPCP-sourced credential theft; described as part of a credential-to-extortion pipeline.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.