Leadership1 distinct publisher3 min readUpdated
Check Point Research says a nonce bug in every public VECT build leaves files above 131,072 bytes unrecoverable, by the attacker as well. That turns extortion into destruction.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
Check Point Research reports that VECT 2.0 does not really encrypt large files, it ruins them: the implementation discards three of four decryption nonces for every file above 131,072 bytes, and CPR states that full recovery is impossible for anyone, the attacker included [1][2][3]. For anyone holding a VECT ransom note, that removes the usual decision entirely, because no payment produces a key that brings back a VM disk, a database or a backup archive [4][5].
The threshold is what does the damage. At 128 KB, almost any file with meaningful business content sits above the line, which CPR says makes VECT a wiper in practice for enterprise assets including VM disks, databases, documents and backups [5]. This is not one affiliate's bad build. The Windows, Linux and ESXi variants share a single libsodium-based encryption engine with the same file-size thresholds, the same four-chunk logic and the same nonce handling, and CPR says it confirmed the flaw across all publicly available VECT versions [6][7]. CPR analyzed the payloads after obtaining access to the panel and builder through a BreachForums account [8].
Two related findings belong in any incident write-up. The cipher has been misidentified in public reporting: VECT uses raw ChaCha20-IETF with no authentication, not the ChaCha20-Poly1305 AEAD claimed in several widely cited threat intelligence reports and in VECT's own initial advertisement, so there is no Poly1305 MAC and no integrity protection [9][10]. And the advertised --fast, --medium and --secure flags on the Linux and ESXi builds are parsed and then silently ignored, with every execution applying the same hardcoded thresholds [11]. An operator who believes they selected a gentler mode did not. CPR also documents self-cancelling string obfuscation, permanently unreachable anti-analysis code and a thread scheduler that degrades the performance it was meant to improve [12].
The practical consequence for a response team is that the negotiation track stops being the long pole. Proof-of-decryption tests on small sample files can pass while everything of value is already gone, since only files at or below the 128 KB threshold are in scope for recovery [4]. Time and budget move to restore validation, integrity checking without any help from the file format [10], and the exfiltration question, which is now the only leverage the actor genuinely holds.
Exposure is a distribution question. VECT appeared in December 2025 on a Russian-language cybercrime forum, shipped 2.0 in February 2026 across Windows, Linux and ESXi, and then announced a partnership with TeamPCP, the actor behind March 2026 supply chain attacks that injected malware into Trivy, Checkmarx' KICS, LiteLLM and Telnyx [13][14][15]. A second deal with BreachForums, in full effect as of April 2026, makes every registered forum user an affiliate with access to the locker, negotiation platform and leak site, where most groups gate entry on reputation or a fee [16][17]. Every one of those affiliates ships the same destructive engine [18]. The counterweight is scale: the leak site currently lists two victims, both from the TeamPCP campaign [19].
Watch for a patched build that restores the discarded nonces, which would make VECT an extortion problem again. Watch the data exfiltration tool listed in the builder but not yet available, since stolen data is the only asset this crew can actually sell back [20]. And watch the promised cloud lockers, which a forum post says will go to affiliates who pass a quiz or puzzle challenge [21].
Ranked by verification strength, evidence, and original report placement.
Check Point Research discovered that the VECT 2.0 ransomware permanently destroys large files rather than encrypting them.
A critical flaw in VECT 2.0's encryption implementation, identical across all three platform variants (Windows, Linux, ESXi), discards three of four decryption nonces for every file above 131,072 bytes (128 KB).
Full recovery of affected files is impossible for anyone, including the attacker.
At a threshold of only 128 KB, the flaw effectively makes VECT a wiper for virtually any file containing meaningful data, including enterprise assets such as VM disks, databases, documents and backups.
The Windows, Linux and ESXi variants share an identical encryption design built on libsodium, with the same file-size thresholds, the same four-chunk logic and the same nonce-handling flaw, confirming a single codebase ported across platforms.
Check Point Research confirmed the nonce flaw is present across all publicly available VECT versions.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed primary reverse engineering, single lab
The findings rest on hands-on analysis of builder-generated Windows, Linux and ESXi payloads with falsifiable specifics: the 131,072-byte threshold, three of four nonces discarded, the named libsodium call crypto_stream_chacha20_ietf_xor, and an on-disk format of ciphertext plus a 12-byte nonce with no MAC. That specificity is strong. It is capped because one vendor lab is the only source in the cluster, no independent lab, CERT or victim confirmation is present, the published body is truncated mid-analysis, and no hashes or samples are supplied for replication.
Broad affiliate access, minimal observed victims
Real-world use appears limited despite wide distribution potential. Cross-platform builds exist and the BreachForums arrangement makes every registered user an affiliate as of April 2026, but the leak site lists only two victims, both inherited from a partner's supply-chain compromise, the exfiltration tool is not yet available, and the promised Cloud Lockers do not exist. Deployment breadth is therefore latent rather than demonstrated.
Finding solid, threat scale ahead of observed impact
The central technical claim is not overstated: the unrecoverability of files above 128 KB and the pointlessness of paying follow directly from the documented nonce handling. The mild positive gap comes from framing severity around enterprise VM disks, databases and backups and an open affiliate pipeline while measured impact is two leak-site victims, an absent exfiltration tool, and no independent verification of the analysis. Notably, the actors' own marketing - AEAD encryption, working speed modes, professional tooling - is what is most overstated here, and this cluster deflates it.
Vendor research with disclosed method, competitive correction
Check Point is a commercial security vendor and this research markets its threat-intelligence capability, including privileged access to an affiliate panel and an explicit correction of 'several widely cited threat intelligence reports' from other analysts. Those are real promotional and competitive incentives. They are partly offset by disclosed methodology, verifiable cryptographic specifics, and conclusions that reduce rather than inflate the perceived sophistication of the threat - a vendor seeking alarm would not emphasize amateur execution and two victims.
Technically strong, structurally single-sourced
Confidence is held mid-range: the cryptographic finding is precise and internally consistent across three variants, but every fact in the cluster traces to one vendor publication whose body is truncated, adoption facts are month-granular actor-forum and leak-site observations, and no second lab, victim, or law-enforcement source is available to check the nonce claim or the victim count.
Follow any of these and your For You feed starts watching them — no settings page required.
security
The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.1 distinct publisher
security
Nitrogen's ESXi encryptor is broken, which means the ransom buys nothing1 distinct publisher
science
LiteLLM 1.82.7 and 1.82.8 shipped an infostealer: rotate everything those machines touched1 distinct publisher
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher