VECT 2.0 Acts as Wiper Due to Encryption Flaw
Patch: update antivirus signatures to detect VECT 2.0 and monitor for its activity.
Patch: update antivirus signatures to detect VECT 2.0 and monitor for its activity.
Summary
Threat hunters warn that the VECT 2.0 operation behaves more like a wiper than ransomware due to a critical flaw in its encryption implementation across Windows, Linux, and ESXi variants. The flaw causes the malware to permanently destroy large files instead of encrypting them, rendering recovery impossible even for the threat actors themselves. Victims who opt to recover their data are left with irrecoverable loss. The operation targets organizations that rely on critical infrastructure and data storage. The flaw was discovered during a forensic analysis of infected systems. VECT 2.0 has been active in the wild for several months. The incident underscores the importance of robust backup strategies. Security teams should update their detection rules to flag VECT 2.0 signatures.
Key changes
- VECT 2.0 acts like a wiper due to encryption flaw
- Permanently destroys large files across Windows, Linux, ESXi
- Recovery impossible even for threat actors
- Active in the wild for months
- Highlights need for robust backups