Skip to content

Leadership1 publisher3 min readPublished

VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless

Check Point Research says a nonce bug in every public VECT build leaves files above 131,072 bytes unrecoverable, by the attacker as well. That turns extortion into destruction.

The Board Room · Leadership desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless
Generated illustration

What happened

  • Check Point Research discovered that the VECT 2.0 ransomware permanently destroys large files rather than encrypting them.
  • A critical flaw in VECT 2.0's encryption implementation, identical across all three platform variants (Windows, Linux, ESXi), discards three of four decryption nonces for every file above 131,072 bytes (128 KB).
  • Full recovery of affected files is impossible for anyone, including the attacker.
  • Paying the ransom cannot restore any file larger than 128 KB; only files at or below the 131,072-byte threshold remain candidates for recovery.
  • At a threshold of only 128 KB, the flaw effectively makes VECT a wiper for virtually any file containing meaningful data, including enterprise assets such as VM disks, databases, documents and backups.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

Check Point Research reports that VECT 2.0 does not really encrypt large files, it ruins them: the implementation discards three of four decryption nonces for every file above 131,072 bytes, and CPR states that full recovery is impossible for anyone, the attacker included [1][2][3]. For anyone holding a VECT ransom note, that removes the usual decision entirely, because no payment produces a key that brings back a VM disk, a database or a backup archive [4][5].

The threshold is what does the damage. At 128 KB, almost any file with meaningful business content sits above the line, which CPR says makes VECT a wiper in practice for enterprise assets including VM disks, databases, documents and backups [5]. This is not one affiliate's bad build. The Windows, Linux and ESXi variants share a single libsodium-based encryption engine with the same file-size thresholds, the same four-chunk logic and the same nonce handling, and CPR says it confirmed the flaw across all publicly available VECT versions [6][7]. CPR analyzed the payloads after obtaining access to the panel and builder through a BreachForums account [8].

Two related findings belong in any incident write-up. The cipher has been misidentified in public reporting: VECT uses raw ChaCha20-IETF with no authentication, not the ChaCha20-Poly1305 AEAD claimed in several widely cited threat intelligence reports and in VECT's own initial advertisement, so there is no Poly1305 MAC and no integrity protection [9][10]. And the advertised --fast, --medium and --secure flags on the Linux and ESXi builds are parsed and then silently ignored, with every execution applying the same hardcoded thresholds [11]. An operator who believes they selected a gentler mode did not. CPR also documents self-cancelling string obfuscation, permanently unreachable anti-analysis code and a thread scheduler that degrades the performance it was meant to improve [12].

The practical consequence for a response team is that the negotiation track stops being the long pole. Proof-of-decryption tests on small sample files can pass while everything of value is already gone, since only files at or below the 128 KB threshold are in scope for recovery [4]. Time and budget move to restore validation, integrity checking without any help from the file format [10], and the exfiltration question, which is now the only leverage the actor genuinely holds.

Exposure is a distribution question. VECT appeared in December 2025 on a Russian-language cybercrime forum, shipped 2.0 in February 2026 across Windows, Linux and ESXi, and then announced a partnership with TeamPCP, the actor behind March 2026 supply chain attacks that injected malware into Trivy, Checkmarx' KICS, LiteLLM and Telnyx [13][14][15]. A second deal with BreachForums, in full effect as of April 2026, makes every registered forum user an affiliate with access to the locker, negotiation platform and leak site, where most groups gate entry on reputation or a fee [16][17]. Every one of those affiliates ships the same destructive engine [18]. The counterweight is scale: the leak site currently lists two victims, both from the TeamPCP campaign [19].

Watch for a patched build that restores the discarded nonces, which would make VECT an extortion problem again. Watch the data exfiltration tool listed in the builder but not yet available, since stolen data is the only asset this crew can actually sell back [20]. And watch the promised cloud lockers, which a forum post says will go to affiliates who pass a quiz or puzzle challenge [21].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories