# VECT

> As of 2026-08-22, VECT is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning ransomware. ATT&CK coverage spans 70 techniques across 15 tactics in 4 of 4 tracked threats. Most-observed techniques: T1021.002 (SMB/Windows Admin Shares), T1485 (Data Destruction), T1489 (Service Stop).

- **Tracked threats:** 4
- **Categories:** RANSOMWARE
- **As of:** 2026-08-22

## ATT&CK techniques observed

70 techniques observed across 4 of 4 tracked threats. Tactics: Discovery (9), Credential Access (7), Execution (7), Impact (7), Lateral Movement (6), Persistence (6).

- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 4 of 4 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 4 of 4 tracked threats
- [T1489](https://intel.threadlinqs.com/technique/T1489) Service Stop — Impact — observed in 4 of 4 tracked threats
- [T1021.004](https://intel.threadlinqs.com/technique/T1021.004) SSH — Lateral Movement — observed in 3 of 4 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 4 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 3 of 4 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 3 of 4 tracked threats
- [T1685](https://intel.threadlinqs.com/technique/T1685) Disable or Modify Tools — Defense Impairment — observed in 3 of 4 tracked threats
- [T1685.005](https://intel.threadlinqs.com/technique/T1685.005) Clear Windows Event Logs — Defense Impairment — observed in 3 of 4 tracked threats
- [T1047](https://intel.threadlinqs.com/technique/T1047) Windows Management Instrumentation — Execution — observed in 2 of 4 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 2 of 4 tracked threats
- [T1059.004](https://intel.threadlinqs.com/technique/T1059.004) Unix Shell — Execution — observed in 2 of 4 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 2 of 4 tracked threats

## Tracked threats

- [VECT 2.0 Ransomware's Nonce-Reuse Flaw Turns It Into an Accidental Wiper for Files Over 128KB](https://intel.threadlinqs.com/threat/TL-2026-2116) — HIGH
- [Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1086) — CRITICAL
- [VECT 2.0 / DEVMAN 3.0 Ransomware — Design-Flawed ChaCha20 Encryption Irreversibly Destroys Files Over 128KB on Windows, Linux & ESXi (Wiper by Accident)](https://intel.threadlinqs.com/threat/TL-2026-0697) — HIGH
- [VECT Ransomware 2.0 — Russian-Speaking RaaS with ChaCha20 Buffer-Reuse Bug Producing Permanent Data Destruction (Wiper-by-Accident) Across Windows, Linux, and ESXi](https://intel.threadlinqs.com/threat/TL-2026-0432) — CRITICAL

## Related CVEs

1 CVE referenced by tracked VECT activity.

- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/VECT
