Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Inside Vect Ransomware-as-a-Service

69aa94434f545b41198b7d21f9acc71457584e62

TLP:CLEAR
Active

SHA-1 Hash

Description

Vect ransomware emerged in January 2026 as a new threat actor operating a Ransomware-as-a-Service program with strategic partnerships that significantly expand its reach. The group has partnered with TeamPCP, known for supply chain attacks compromising security tools like Trivy, KICS, and LiteLLM, and BreachForums, distributing affiliate keys to forum members. With 25 published victims primarily targeting the United States and Technology sector, Vect maintains an open affiliate program requiring only a $250 invite code. The operation offers multi-platform ransomware payloads for Windows, Linux, and ESXi with sophisticated lateral movement capabilities and tiered commission structures reaching 89% for top affiliates. Analysis reveals connections to the defunct Devman ransomware through shared code strings and ransom note similarities, suggesting possible rebranding or code reuse.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Inside Vect Ransomware-as-a-Service
Pattern Type
STIX
Confidence
75%
Valid From
May 6, 2026 04:50
Total Sightings
0
Added
May 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 69aa94434f545b41198b7d21f9acc71457584e62

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.