INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Vect 2.0 Ransomware Exploits Design Flaw to Act as Wiper
| 2026-04-29 15:23 CRITICAL HIGH RANSOMWARE & EXTORTION DATA BREACH MALWARE & BOTNETS
Executive Summary
AI-generated
On April 29, 2026, the Vect 2.0 ransomware variant was found to have a design error that makes it act as a wiper, deleting large files instead of encrypting them, affecting organizations with Windows, Linux, and VMware ESXi systems worldwide. The flaw affects files over 128KB in size, rendering decryption impossible for defenders even if they pay the ransom. This means victims will not be able to recover their largest files, including enterprise assets such as VM disks, databases, documents, and backups. The attack works by exploiting a ChaCha20-IETF encryption scheme that discards three of four decryption nonces for every large file above 128KB, making it virtually impossible to decrypt the affected data. As of now, no specific entity has been attributed to the incident, but Check Point Software reported on the vulnerability in their latest article.
Technical Mitigations AI-generated
• Patch Vect 2.0 to fix the ChaCha20-IETF encryption scheme flaw that discards three of four decryption nonces for files above 128KB.
• Use a detection technique to identify files with irrecoverably destroyed first three nonces, such as analyzing file metadata or disk space usage patterns.
• Block or hunt for Vect's use of the ChaCha20-IETF encryption scheme and its specific nonce values (12 bytes) in encrypted files.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
se•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Tropic TrooperTropic Trooper
WiperWiper
Target & Sectors
DPRK
DPRK
educationeducation
healthhealth
technologytechnology
Incident Timeline
2026/04/29
The Vect 2.0 ransomware-as-service operation inadvertently and permanently destroys large files instead of encrypting them due to a design error in its ChaCha20-IETF encryption scheme, rendering it as a wiper malware.
Click on any entity below to view its context and source!
infrastructure
Macos
Related:
North Korea's Lazarus Targets macOS Users via ClickFix
For defenders, this makes the situation slightly worse, as they no longer will be able to recover all of their files, even if they agree to
pay the ransom
to do so, Check Point says.
financial
2.0 Ransomware Acts
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error.
infrastructure
2.0
The Vect 2.0 variant of the
ransomware-as-service
(RaaS) operation, which first appeared last December, has a flaw across its versions for Windows, Linux, and VMware ESXi that inadvertently and permanently destroys so-called "large files" rather…
data_breach
12 generated random byte nonces
"
ChaCha20-IETF requires both the 32 byte key and the exact matching 12 byte nonce to unlock each chunk of data, so the first three quarters of every large file are unrecoverable by anyone — even the ransomware operators themselves.
Feuding Ransomware Groups Leak Each Other's Data
The Vect Flaw, Unpacked
The flaw exists because, according to Vect's ChaCha20-IETF encryption scheme, the malware encrypts four independent chunks of each "large file" using four freshly generated ran…
data_breach
32 byte key
"
ChaCha20-IETF requires both the 32 byte key and the exact matching 12 byte nonce to unlock each chunk of data, so the first three quarters of every large file are unrecoverable by anyone — even the ransomware operators themselves.
infrastructure
Windows
…ant of the
ransomware-as-service
(RaaS) operation, which first appeared last December, has a flaw across its versions for Windows, Linux, and VMware ESXi that inadvertently and permanently destroys so-called "large files" rather than encrypting t…
For Windows systems, security teams should monitor for PowerShell-based disabling of Windows Defender, event log clearing activity, and suspicious safe-mode boot configuration changes, all of which are key behavioral indicators of
Vect ransomware…
infrastructure
Linux
…e
ransomware-as-service
(RaaS) operation, which first appeared last December, has a flaw across its versions for Windows, Linux, and VMware ESXi that inadvertently and permanently destroys so-called "large files" rather than encrypting them, acco…
threat_actor
Tropic Trooper
Related:
Tropic Trooper APT Takes Aim at Home Routers, Japanese Targets
"These are exactly the environments where file destruction, not mere encryption, causes the most irreversible damage," the team at Secure.com wrote.
data_breach
131,072 bytes
Check Point
has confirmed that the flaw, which "discards three of four decryption nonces for every file above 131,072 bytes (128 KB)," is identical across all three platform variants.
Tactical Metrics
Metrics
infrastructure
Macos
Affected Product
Click for context!
Related:
North Korea's Lazarus Targets macOS Users via ClickFix
For defenders, this makes the situation slightly worse, as they no longer will be able to recover all of their files, even if they agree to
pay the ransom
to do so, Check Point says.
Metrics
financial
2
Ransomware Acts
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error.
Metrics
infrastructure
Windows
Affected Product
…ant of the
ransomware-as-service
(RaaS) operation, which first appeared last December, has a flaw across its versions for Windows, Linux, and VMware ESXi that inadvertently and permanently destroys so-called "large files" rather than encrypting t…
For Windows systems, security teams should monitor for PowerShell-based disabling of Windows Defender, event log clearing activity, and suspicious safe-mode boot configuration changes, all of which are key behavioral indicators of
Vect ransomware…
Metrics
infrastructure
Linux
Affected Product
…e
ransomware-as-service
(RaaS) operation, which first appeared last December, has a flaw across its versions for Windows, Linux, and VMware ESXi that inadvertently and permanently destroys so-called "large files" rather than encrypting them, acco…
Metrics
infrastructure
2.0
Software Version
The Vect 2.0 variant of the
ransomware-as-service
(RaaS) operation, which first appeared last December, has a flaw across its versions for Windows, Linux, and VMware ESXi that inadvertently and permanently destroys so-called "large files" rather…
Metrics
data_breach
12
Generated Random Byte Nonces
Feuding Ransomware Groups Leak Each Other's Data
The Vect Flaw, Unpacked
The flaw exists because, according to Vect's ChaCha20-IETF encryption scheme, the malware encrypts four independent chunks of each "large file" using four freshly generated ran…
"
ChaCha20-IETF requires both the 32 byte key and the exact matching 12 byte nonce to unlock each chunk of data, so the first three quarters of every large file are unrecoverable by anyone — even the ransomware operators themselves.
Metrics
data_breach
32
Byte Key
"
ChaCha20-IETF requires both the 32 byte key and the exact matching 12 byte nonce to unlock each chunk of data, so the first three quarters of every large file are unrecoverable by anyone — even the ransomware operators themselves.
Metrics
data_breach
131,072
Bytes
Check Point
has confirmed that the flaw, which "discards three of four decryption nonces for every file above 131,072 bytes (128 KB)," is identical across all three platform variants.
Intelligence Sources
Dark Reading
2026-04-29
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:19
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Lazarus Targets macOS Users
entity
4x
timeline
Temporal Reference
2025/04/29
date
3x
target region
Target Country
Korea, Democratic People's Republic of
country
3x
infrastructure
Affected Product
Macos
software
3x
tactic
Cyber Operation Type
Ransomware
tactic
3x
attribution
Attributing Entity
Reflections
authority
2x
tactic
MITRE ATT&CK Technique
T1592.002 - Software
technique
Contextual Telemetry
Context Block
11 METRICS
target region
Target Region
DPRK
region
malware
Malware Payload
Wiper
tool
financial
Ransomware Acts
2
ransomware acts
infrastructure
Software Version
2.0
version
general metric
Variant
2
variant
general metric
Kb
128
kb
data breach
Generated Random Byte Nonces
12
generated random byte nonces
data breach
Byte Key
32
byte key
general metric
Years
13
years
threat actor
APT Group
Tropic Trooper
actor
data breach
Bytes
131,072
bytes
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.