‘VECT is marketed as ransomware… but works as a data destruction tool’: Experts warn this ‘broken’ ransomware now acts as a data wiper, so protect your files now



  • New ransomware variant found to work as a destructive data wiper
  • Faulty nonce handling causes files larger than 128KB to be permanently lost
  • Despite being marketed as RaaS, victims cannot recover data even if they pay

VECT 2.0, a relatively new ransomware variant offered for sale on dark web forums, does not actually work and functions as a data wiper rather than an encryptor, researchers warn.

In a new in-depth report, cybersecurity team Check Point explained that the problem is in the way VECT 2.0 handles “nonces”: random values ​​needed to properly encrypt and then decrypt data. Apparently, the malware splits large files into fragments, but instead of using new memory space each time, it reuses it, thus overwriting the previous one.

Leave a Comment

Your email address will not be published. Required fields are marked *