VECT is a criminal RaaS group from December 2025 known for a flawed ransomware payload that irreversibly destroys files.
Analyst brief
VECT is a criminal Ransomware-as-a-Service (RaaS) group that emerged in December 2025 with a five-tier revenue-sharing model and a formal partnership with BreachForums. The group's primary TTP involves a VECT 2.0 payload that contains a critical flaw, irreversibly destroying files larger than 128 KB instead of encrypting them. Defenders should prioritize detection of this specific payload, as its deployment can lead to permanent data destruction rather than a traditional ransomware scenario.
vect
activecrime
VECT is a RaaS group that launched its affiliate program in December 2025 with a five-tier revenue-sharing model and a formal partnership with BreachForums; its VECT 2.0 payload contains a critical encryption flaw that irreversibly destroys files larger than 128 KB rather than encrypting them.