Briefing

VECT 2.0 Acts as Wiper Due to Encryption Flaw

security
by [email protected] (The Hacker News) ·

Patch: update antivirus signatures to detect VECT 2.0 and monitor for its activity.

What to do now

Patch: update antivirus signatures to detect VECT 2.0 and monitor for its activity.

Summary

Threat hunters warn that the VECT 2.0 operation behaves more like a wiper than ransomware due to a critical flaw in its encryption implementation across Windows, Linux, and ESXi variants. The flaw causes the malware to permanently destroy large files instead of encrypting them, rendering recovery impossible even for the threat actors themselves. Victims who opt to recover their data are left with irrecoverable loss. The operation targets organizations that rely on critical infrastructure and data storage. The flaw was discovered during a forensic analysis of infected systems. VECT 2.0 has been active in the wild for several months. The incident underscores the importance of robust backup strategies. Security teams should update their detection rules to flag VECT 2.0 signatures.

Key changes

  • VECT 2.0 acts like a wiper due to encryption flaw
  • Permanently destroys large files across Windows, Linux, ESXi
  • Recovery impossible even for threat actors
  • Active in the wild for months
  • Highlights need for robust backups

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting