#threatreport #HighCompleteness
Dark Web Profile: Vect Ransomware | 05-06-2026
Source:
socradar.io/blog/dark-web-pr…
Key details below ↓
🧑💻Actors/Campaigns:
Vect (🧠motivation: financially_motivated)
Teampcp
Dragonforce
💀Threats:
Supply_chain_technique, Conti, Lockbit, Qtox_tool, Devman, Credential_harvesting_technique, Shadow_copies_delete_technique, Winrm_tool, Rclone_tool, Canisterworm, Windows_locker,
🎯Victims: Technology, Financial services, Healthcare, Manufacturing, Business services, Energy, Consumer services, Education, Agriculture & food production
🏭Industry: Healthcare, Foodtech, E-commerce, Education, Energy
🌐Geo: Kazakhstan, South africa, Russia, Egypt, India, Ukraine, Africa, Brazil, Israel, Belarus, Spain, Italy
📚TTPs:
⚔️Tactics: 10
🛠️Technics: 31
🧨IOCs:
- File: 3
- Command: 1
💽Software: Trivy, LiteLLM, Linux, ESXi, Kubernetes, Microsoft Defender, MariaDB, MySQL, PostgreSQL, Redis, ...
🪙Crypto: monero, bitcoin
🔢Algorithms: base64, chacha20-poly1305, chacha20, poly1305, xor
🔠Functions: randombytes, Set-MpPreference
🗂️Win API: NtQueryInformationProcess, NetShareEnum, MoveFileExW
📜Programming Languages: powershell, python
#threatreport:
Vect ransomware emerged on December 31, 2025, as a financially motivated double-extortion ransomware-as-a-service operation, advertised on a Russian-language cybercrime forum. The group rapidly established a broad affiliate network, publishing their first 25 victims within four months, and formed alliances that connect them to other cyber threat actors, notably TeamPCP. This partnership enables them to leverage credentials harvested from multiple supply chain compromises, including significant breaches in Trivy and Checkmarx KICS.
The Vect ransomware operates through a structured affiliate model, offering one of the lowest entry costs in the ransomware ecosystem at $250 paid in Monero, with waivers for applicants from the Commonwealth of Independent States (CIS). Affiliates gain access to functionality such as a payload builder for various operating systems and a collaborative platform for negotiating with victims. By mid-April 2026, a significant milestone occurred with BreachForums distributing Vect affiliation keys to its entire registered user base, effectively expanding the recruitment pool dramatically without the usual skill or experience requirements.
Attacks initiated by Vect typically exploit supply chain vulnerabilities, particularly those exploited in the TeamPCP campaign that targeted multiple software development tools and services. Initial access is achieved through compromise during CI/CD pipelines, allowing them to harvest sensitive credentials, leading to substantial data exfiltration. The encryption process itself operates with a high potential for data loss due to a flaw in their encryption methodology, which inadvertently renders large portions of encrypted files unrecoverable. The Vect encryption routine employs the ChaCha20 algorithm but fails to provide message integrity protection, further destabilizing the viability of victim recovery efforts.
Vect’s operational techniques include disabling security mechanisms before executing their ransomware, terminating protective services, and conducting thorough system reconnaissance to maintain an effective foothold. They perform lateral movement through methods that masquerade as legitimate system operations, using scheduled tasks to escalate privileges and propagate throughout networks. Their impact extends across various sectors, with notable concentrations of victims located in the United States and Brazil, while the technology sector suffers the most significant breaches.
To defend against Vect ransomware, organizations are advised to promptly rotate any potentially compromised credentials and implement stringent network defenses, especially against Tor traffic, where Vect maintains its command-and-control infrastructure. Monitoring for specific behaviors associated with Vect operations, along with rigorous logging and alerting for unusual system modifications, is essential for detection and prevention. Finally, maintaining immutable backups and following best practices for patch management and security configurations can mitigate the risks associated with this ransomware threat.