TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

Critical Flaw Turns Vect Ransomware into Data Destroying Wiper

2026-04-29 · Read original ↗

ATT&CK techniques detected

8 predictions
T1486Data Encrypted for Impact
98%
“were permanently destroyed rather than being encrypted. this is due to a critical flaw in the encryption implementation of the ransomware that discards three of four decryption nonces – one - time secret numbers used in an authentication protocol to ensure that each cryptographic…”
T1486Data Encrypted for Impact
96%
“use of the vect ransomware, negotiation platform and leak site for operations. “ as of april 2026, this partnership is in full effect, ” the check point researchers noted in a new report published on april 28. vect 2. 0 : raas ambitions crumble under poor implementation allegedly…”
T1486Data Encrypted for Impact
87%
“critical flaw turns vect ransomware into data destroying wiper vect 2. 0 ransomware has been found to wipes large, compromised files instead of merely encrypting them, making recovery impossible – even for the attackers. this is due to a critical flaw in the encryption implementa…”
T1486Data Encrypted for Impact
84%
“with the same file - size thresholds, the same four - chunk logic and the same nonce - handling flaw throughout, “ confirming a single codebase ported across platforms, ” the report noted. additionally, the check point researchers identified multiple additional bugs and design fa…”
T1564.006Run Virtual Instance
58%
“use of the vect ransomware, negotiation platform and leak site for operations. “ as of april 2026, this partnership is in full effect, ” the check point researchers noted in a new report published on april 28. vect 2. 0 : raas ambitions crumble under poor implementation allegedly…”
T1485Data Destruction
55%
“critical flaw turns vect ransomware into data destroying wiper vect 2. 0 ransomware has been found to wipes large, compromised files instead of merely encrypting them, making recovery impossible – even for the attackers. this is due to a critical flaw in the encryption implementa…”
T1679Selective Exclusion
36%
“were permanently destroyed rather than being encrypted. this is due to a critical flaw in the encryption implementation of the ransomware that discards three of four decryption nonces – one - time secret numbers used in an authentication protocol to ensure that each cryptographic…”
T1490Inhibit System Recovery
36%
“critical flaw turns vect ransomware into data destroying wiper vect 2. 0 ransomware has been found to wipes large, compromised files instead of merely encrypting them, making recovery impossible – even for the attackers. this is due to a critical flaw in the encryption implementa…”

Summary

The Vect 2.0 ransomware wipes large files instead of merely encrypting them, making recovery impossible – even for the attackers