# Vect Ransomware

> As of 2026-07-27, Vect Ransomware is a threat actor tracked by Threadlinqs Intelligence across 2 threats spanning ransomware, supply chain. ATT&CK coverage spans 59 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1021 (Remote Services), T1027 (Obfuscated Files or Information), T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 2
- **Categories:** RANSOMWARE, SUPPLY_CHAIN
- **As of:** 2026-07-27

## ATT&CK techniques observed

59 techniques observed across 2 of 2 tracked threats. Tactics: Impact (8), Execution (7), Discovery (6), Persistence (6), Stealth (formerly Defense Evasion) (5), Command and Control (4).

- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 2 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 2 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 2 of 2 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1195](https://intel.threadlinqs.com/technique/T1195) Supply Chain Compromise — Initial Access — observed in 2 of 2 tracked threats
- [T1485](https://intel.threadlinqs.com/technique/T1485) Data Destruction — Impact — observed in 2 of 2 tracked threats
- [T1486](https://intel.threadlinqs.com/technique/T1486) Data Encrypted for Impact — Impact — observed in 2 of 2 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 2 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 1 of 2 tracked threats
- [T1021.004](https://intel.threadlinqs.com/technique/T1021.004) SSH — Lateral Movement — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Execution — observed in 1 of 2 tracked threats

## Tracked threats

- [VECT Ransomware 2.0 — Russian-Speaking RaaS with ChaCha20 Buffer-Reuse Bug Producing Permanent Data Destruction (Wiper-by-Accident) Across Windows, Linux, and ESXi](https://intel.threadlinqs.com/threat/TL-2026-0432) — CRITICAL
- [TeamPCP Partners With Vect Ransomware Group to Escalate Cross-Ecosystem Open Source Supply Chain Attacks](https://intel.threadlinqs.com/threat/TL-2026-0288) — CRITICAL

## Related CVEs

1 CVE referenced by tracked Vect Ransomware activity.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Vect%20Ransomware
