Vect CTI Report
ID: 76107829-1fa9-40b7-97f1-d524e547433a
STIX ID: report--76107829-1fa9-40b7-97f1-d524e547433a
Threat Score
78/100
Uploaded: 2026-06-10
Published Date: 2026-06-10
Last Modified Date: 2026-06-10
Created by: dogesec
TLP:CLEAR
...
...
RansomLook's reverse-engineered analysis of VECT 2.0 (Windows x64) describes a sophisticated Active Directory-targeting ransomware with ten PowerShell lateral primitives, Safe Mode persistence, backup/service disruption, and enterprise-focused killlists; however, the build contains a hardcoded ChaCha20 key and a lost-nonce bug that makes files >128 KiB permanently unrecoverable, no exfiltration code was found, and small files remain decryptable with the extracted key.
