INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Ransomware by design, Wiper by accident

| 2026-04-28 13:03 CRITICAL HIGH
Executive Summary AI-generated
Background VECT ransomware, a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum, has been observed removing Ukraine from the CIS countries list during times of conflict. This is an uncommon trend, suggesting that the code used by VECT may be AI-generated or based on outdated technology. The ransomware's ability to exfiltrate sensitive data and publish it online if not paid for demonstrates its potential impact. Its use as a wiper, permanently destroying large files rather than encrypting them, makes it particularly destructive in terms of data loss.
Technical Mitigations AI-generated
• The encryption implementation in VECT ransomware is flawed, specifically the decryption nonces are discarded for files above 131,072 bytes (128 KB), making it a wiper rather than encrypting data. • The cipher used by VECT is misidentified as ChaCha20-Poly1305 AEAD when it actually uses raw ChaCha20-IETF with no authentication and Poly1305 MAC without integrity protection. • The encryption speed modes advertised across Linux and ESXi variants are not implemented, leading to identical hardcoded thresholds for all platforms.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
WiperWiper
Target & Sectors
GCC GCC CIS CIS NORTH_AMERICA NORTH_AMERICA healthhealth defensedefense
Incident Timeline
‎December 2025
Russian Federation launched VECT Ransomware on December 2025.
target_region Russian Federation
tactic Ransomware
‎January 2026
The actor claimed their first two victims in January 2026 and subsequently announced a partnership with TeamPCP.
‎February 2026
The ransomware targets VMware ESXi hypervisors and employs geofencing before disrupting system services, wiping logs, and encrypting victim files.
tactic Ransomware
infrastructure Windows
infrastructure Linux
infrastructure 2.0
general_metric 2.0 version
organisation Delete
organisation The Hypervisor Ransomware
organisation the VMware File System
organisation Ransomware Cross-Platform Overview
organisation VMware
victims 2.0 targets
data_breach 32 byte
data_breach 12 byte
organisation KB
organisation SSH
organisation Anti-Analysis
organisation Check Point Research’s
organisation WMI
organisation SSH / SCP Geofencing / CIS
organisation Lateral Movement
organisation SystemFunction036 / RtlGenRandom
organisation ProcessPrng
organisation Process and Service Disruption
organisation DCOM/MMC
organisation Anti-Analysis The Windows
organisation XOR
organisation Rotate
organisation Wildcards
data_breach 131,072 bytes
organisation Small File Processing For
data_breach 32,768 bytes
organisation Large File Processing
organisation Impact File
organisation Shell
organisation Command-Line Interface
organisation Cipher ChaCha20-IETF
organisation ChaCha20-IETF
financial 4 offset formula
organisation Bernstein’s
organisation EOF
organisation LockBit
organisation CPU
organisation ProgramData
organisation Shell & command
organisation TracerPid
organisation Cross-Platform Confirmation The
organisation VMDK
organisation Command-Line Interface and
organisation Default Behavior
organisation GPO
organisation Group Policy
organisation File Encryption and Renaming Each
organisation Target Selection and
organisation x64dbg
organisation ssh Service Disruption
organisation VMware File System
organisation ASCII
organisation Dear Management
organisation ChaCha20
data_breach 16 byte
data_breach 4 small files
‎March 2026
VECT announced a partnership with BreachForums, allowing registered users to become affiliates and use VECT ransomware.
organisation VECT
organisation BreachForums
‎2026/04/28
The ransomware, VECT: Ransomware by design, Wiper by accident, exploits a critical flaw in its encryption implementation that allows it to target files larger than 131,072 bytes.
organisation Ransomware
organisation Check Point Research
financial 2.0 ransomware
infrastructure Windows
infrastructure Linux
data_breach 131,072 bytes
organisation Target
organisation MB
data_breach 64 MB
organisation CPR
organisation MAC
‎April 2026
The incident is attributed to a partnership between two cybersecurity firms, VECT and Ransomwarebytes.
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
financial
2
Ransomware
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎2.0
Software Version
Metrics
victims
2
Targets
Metrics
data_breach
32
Byte
Metrics
data_breach
12
Byte
Metrics
data_breach
64
Mb
Metrics
data_breach
131,072
Bytes
Metrics
financial
4
Offset Formula
Metrics
data_breach
32,768
Bytes
Metrics
data_breach
16
Byte
Metrics
data_breach
4
Small Files
Intelligence Sources
Zero Day Fans 2026-04-28
Zero Day Fans 2026-04-28