VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a formal partnership with BreachForums; its VECT 2.0 payload contains a critical encryption flaw that irreversibly destroys files larger than 128 KB rather than encrypting them.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
/*
vect ransomware
*/
rule vect_Ransomnote
{
meta:
author = "ransomware.live"
family = "ransomware.vect"
description = "Detects vect ransomware ransom note or artifact"
date = "2026-05-04"
severity = 7
score = 70
strings:
$name1 = "vect" ascii nocase
$name2 = "VECT" ascii
$onion = "vect.onion" ascii nocase
condition:
any of them
}
!!! README !!!
===============================================================
::: ::: :::::::::: :::::::: :::::::::::
:+: :+: :+: :+: :+: :+:
+:+ +:+ +:+ +:+ +:+
+#+ +:+ +#++:++# +#+ +#+
+#+ +#+ +#+ +#+ +#+
#+#+#+# #+# #+# #+# #+#
### ########## ######## ###
===============================================================
Dear Management, all of your files have been encrypted with ChaCha20 which is an unbreakable encryption algorithm.
Sadly, this is not the only bad news for you. We have also exfiltrated your sensitive data, consisting mostly of databases, backups and other personal information
from your company and will be published on our website if you do not cooperate with us.
The only way to recover your files is to get the decryption tool from us.
To obtain the decryption tool, you need to:
1. Open Tor Browser and visit: [redactado]
2. Follow the instructions on the chat page
3. Receive a sample decryption of up to 4 small files
4. We will provide payment instructions
5. After payment, you will receive decryption tool
WARNING:
- Do not modify encrypted files
- Do not use third party software to restore files
- Do not reinstall system
If you violate these rules, your files will be permanently damaged.
Files encrypted: 0
Total size: 0 bytes
Unique ID: [snip]
Backup contact ([redactado] [redactado]Status: STATUS: NEGOTIATING | Sector: Energy | DATA SIZE: 238GB | Deadline: 22d 3h
Status: STATUS: NEGOTIATING | Sector: Seller | ├─ Web server and local development environment files ├─ Database and SQL server data directories ├─ Business/ERP and accounting application data ├─ Shared company network data directories ├─ Micr... DATA SIZE: 30.26 GB | Deadline: 18d 19h
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| Verlat Energy | PE | Energy | — | 4 mar 2026 |
| Sus Insumos S.A.S | CO | Agriculture and Food Production | — | 25 feb 2026 |
| Del Rey | BR | Business Services | — | 25 feb 2026 |
| Auvo | BR | Technology | — | 24 feb 2026 |
| Was Madeiras | BR | Manufacturing | — | 24 feb 2026 |
| Mutualista Imbabura | EC | Financial Services | — | 24 feb 2026 |
| MB Contabilidade | BR | Business Services | — | 24 feb 2026 |
| Federal University of Sergipe | BR | Education | — | 8 ene 2026 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética
Status: STATUS: NEGOTIATING | Sector: IT | Legal and individual case process files Service orders and external work orders Sewage and maintenance service documentation Recruitment records and job vacancy registrations Gover... | Deadline: 18d 19h
Status: STATUS: LEAKED | Sector: IT | │ ├─Purchasing and procurement records │ ├─Supplier and vendor documentation │ ├─Purchase orders and order history │ ├─Quotations and pricing negotiations │ ├─Fabric and materials specificatio... DATA SIZE: 372.78 GB
Status: STATUS: LEAKED | Sector: Manifacturer | Production control records Daily production logs Manufacturing scheduling data (multiple plants) Assembly and mounting control records Shipping and expedition records Warehous... DATA SIZE: 151GB
Status: STATUS: LEAKED | Sector: Finance | Customer financial records (loans, savings, balances) Credit and loan portfolio data Payroll and salary information Employee personal data (PII) National ID documents Customer... DATA SIZE: 300GB