logo

Vect CTI Report

ID: 76107829-1fa9-40b7-97f1-d524e547433a

STIX ID: report--76107829-1fa9-40b7-97f1-d524e547433a

Threat Score

78/100

Uploaded: 2026-06-10

Created by: dogesec

TLP:CLEAR
...
...
RansomLook's reverse-engineered analysis of VECT 2.0 (Windows x64) describes a sophisticated Active Directory-targeting ransomware with ten PowerShell lateral primitives, Safe Mode persistence, backup/service disruption, and enterprise-focused killlists; however, the build contains a hardcoded ChaCha20 key and a lost-nonce bug that makes files >128 KiB permanently unrecoverable, no exfiltration code was found, and small files remain decryptable with the extracted key.