Ransomware Group intelligence
Vect
InactiveTrack Vect with 25 published victims and 3 known leak locations in a single intelligence view.
Overview
Vect is tracked by Breach House as a ransomware group with 25 published victims.
Brazil is currently the most targeted country in this dataset.
3 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (3)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 3 | Onion service | Down checked 53m ago | breach5yz2b5lepmq4gaqwcon3jippw3bislhvvdavem5git55sy2nid.onion |
| Leak location 2 | Onion service | Down checked 53m ago | vectordntlcrlmfkcm4alni734tbcrnd5lk44v6sp4lqal6noqrgnbyd.onion |
| Leak location 1 | Onion service | Down checked 53m ago | bu7zr6fotni3qxxoxlcmpikwtp5mjzy7jkxt7akflnm2kwkbdtgtjuid.onion |
Top Activity Sectors (11)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Vect, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1047 Windows Management Instrumentation Execution
What they do: vect uses Windows Management Instrumentation to execute commands and maintain persistence across systems.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
T1059.001 PowerShell Execution
What they do: vect uses PowerShell to execute malicious payloads and stage ransomware binaries across targeted systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: vect modifies Registry Run Keys to ensure ransomware execution upon user logon or system startup.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: vect disables antivirus and monitoring tools using registry modifications to evade detection during deployment.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: vect deletes Volume Shadow Copies and backup files via system commands to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1003.001 LSASS Memory Credential Access
What they do: vect accesses LSASS memory to steal credentials for lateral movement and privilege escalation.
What that means: Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
-
T1135 Network Share Discovery Discovery
What they do: vect probes network shares to identify victim directories and expand encryption targets efficiently.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: vect leverages SMB/Windows Admin Shares for lateral movement between compromised hosts in the same network.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: vect encrypts critical files using its ransomware payload, applying impact to Finance, Healthcare, and Manufacturing victims.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: vect calls system recovery inhibitors to block backup restoration and maximize operational disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
!!!_READ_ME_!!!.txt
!!! README !!!
===============================================================
::: ::: :::::::::: :::::::: :::::::::::
:+: :+: :+: :+: :+: :+:
+:+ +:+ +:+ +:+ +:+
+#+ +:+ +#++:++# +#+ +#+
+#+ +#+ +#+ +#+ +#+
#+#+#+# #+# #+# #+# #+#
### ########## ######## ###
===============================================================
Dear Management, all of your files have been encrypted with ChaCha20 which is an unbreakable encryption algorithm.
Sadly, this is not the only bad news for you. We have also exfiltrated your sensitive data, consisting mostly of databases, backups and other personal information
from your company and will be published on our website if you do not cooperate with us.
The only way to recover your files is to get the decryption tool from us.
To obtain the decryption tool, you need to:
1. Open Tor Browser and visit: http://vectordntlcrlmfkcm4alni734tbcrnd5lk44v6sp4lqal6noqrgnbyd.onion/chat/[snip]
2. Follow the instructions on the chat page
3. Receive a sample decryption of up to 4 small files
4. We will provide payment instructions
5. After payment, you will receive decryption tool
WARNING:
- Do not modify encrypted files
- Do not use third party software to restore files
- Do not reinstall system
If you violate these rules, your files will be permanently damaged.
Files encrypted: 0
Total size: 0 bytes
Unique ID: [snip]
Backup contact (Qtox): 1A51DCBB33FBF603B385D223F599C6D64545E631F7C870FFEA320D84CE5DAF076C1F94100B5B
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (25)
Search, filter and paginate the victim timeline for Vect. Showing 1–25 of 25.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | S&PGLOBAL, LiteLLM/Trivy campaign (TeamPCP) id28244 View details | United States | Finance / Legal / Insurance | — | |
|
Status: STATUS: NEGOTIATING | Sector: Business Services | Internal projects, secrets, api keys etc DATA SIZE: 250GB | Deadline: 8d 8h |
|||||
| Ransomware | guesty, LITELLM/TRIVY CAMPAIGN (TEAMPCP) id28243 View details | Israel | Hospitality / Food & Beverage / Tourism | — | |
|
Status: STATUS: NEGOTIATING | Sector: property management | internal projects, 4 million sent/received mails with attachments, userbase, Airbnb and booking.com data stolen from guesty DATA SIZE: 700GB | Deadline: 9d 8h |
|||||
| Ransomware | Verlat Energy id27046 View details | Peru | Energy | — | |
|
Status: STATUS: NEGOTIATING | Sector: Energy | DATA SIZE: 238GB | Deadline: 22d 3h |
|||||
| Ransomware | USHA International Limited id26935 View details | India | Services | — | |
|
Status: STATUS: NEGOTIATING | Sector: manufacturer | Employee Data, CMS, CMR, SAP databases. | Deadline: 19d 11h |
|||||
| Ransomware | jdaas id26919 View details | India | Finance / Legal / Insurance | — | |
|
Status: STATUS: NEGOTIATING | Sector: IT | backups, source codes, financial records, and so on DATA SIZE: 600GB | Deadline: 20d 7h |
|||||
| Ransomware | Casas del Mediterraneo id26918 View details | Spain | Construction / Real Estate | — | |
|
Status: STATUS: NEGOTIATING | Sector: Real Estate | DATA SIZE: 200GB | Deadline: 29d 7h |
|||||
| Ransomware | keliweb id26917 View details | Italy | Other | — | |
|
Status: STATUS: NEGOTIATING | Sector: IT | DATA SIZE: 200GB | Deadline: 28d 7h |
|||||
| Ransomware | Sus Insumos S.A.S id26853 View details | Colombia | Finance / Legal / Insurance | — | |
|
Status: STATUS: NEGOTIATING | Sector: Seller | ├─ Web server and local development environment files ├─ Database and SQL server data directories ├─ Business/ERP and accounting application data ├─ Shared company network data directories ├─ Micr... DATA SIZE: 30.26 GB | Deadline: 18d 19h |
|||||
| Ransomware | Del Rey id26852 View details | Brazil | Finance / Legal / Insurance | — | |
|
Status: STATUS: NEGOTIATING | Sector: IT | Legal and individual case process files Service orders and external work orders Sewage and maintenance service documentation Recruitment records and job vacancy registrations Gover... | Deadline: 18d 19h |
|||||
| Ransomware | Auvo id26830 View details | Brazil | Communication / Marketing | — | |
|
Status: STATUS: LEAKED | Sector: IT | │ ├─Purchasing and procurement records │ ├─Supplier and vendor documentation │ ├─Purchase orders and order history │ ├─Quotations and pricing negotiations │ ├─Fabric and materials specificatio... DATA SIZE: 372.78 GB |
|||||
| Ransomware | Grupo VerdeAzul id26829 View details | Namibia | Finance / Legal / Insurance | — | |
|
Status: STATUS: LEAKED | Sector: asset management | │ ├─Accounting and bookkeeping system data (Sage / Peachtree) │ ├─Company financial records and ledgers │ ├─Accounts payable and receivable data │ ├─Tax configuration and tax table files │ ├─Payro... DATA SIZE: 13.36 GB |
|||||
| Ransomware | Was Madeiras id26828 View details | Brazil | Manufacturing / Engineering | — | |
|
Status: STATUS: LEAKED | Sector: Manifacturer | Production control records Daily production logs Manufacturing scheduling data (multiple plants) Assembly and mounting control records Shipping and expedition records Warehous... DATA SIZE: 151GB |
|||||
| Ransomware | Mutualista Imbabura id26827 View details | Ecuador | Finance / Legal / Insurance | — | |
|
Status: STATUS: LEAKED | Sector: Finance | Customer financial records (loans, savings, balances) Credit and loan portfolio data Payroll and salary information Employee personal data (PII) National ID documents Customer... DATA SIZE: 300GB |
|||||
| Ransomware | EnerTec id26826 View details | South Africa | Manufacturing / Engineering | — | |
|
Status: STATUS: LEAKED | Sector: Manufacturing | Databases Documents Contracts blueprints and so on DATA SIZE: 151.79 GB |
|||||
| Ransomware | ApexHospitals id26825 View details | India | Healthcare / Pharma | — | |
|
Status: STATUS: LEAKED | Sector: healthcare | Employee personally identifiable information (PII) Payroll records and compensation data Social Security numbers / national ID numbers Complete patient medical records Medical histories and clinic... |
|||||
| Ransomware | MB Contabilidade id26824 View details | Brazil | Finance / Legal / Insurance | — | |
|
Status: STATUS: NEGOTIATING | Sector: accounting | ├─ Public/shared company directories (general, accounting I & II, HR, legal, indexes, systems, tokens) ├─ Accounting system data and balance databases (multiple company instances) ├─ Client/company... DATA SIZE: 121.03 GB | Deadline: 8d 4h |
|||||
| Ransomware | s***om****x id26823 View details | United States | Healthcare / Pharma | — | |
|
Status: STATUS: NEGOTIATING | Sector: Healthcare | PII data, clients medical records, and HIV tests | Deadline: 18d 7h |
|||||
| Ransomware | a*f***a id26822 View details | EU | Healthcare / Pharma | — | |
|
Status: STATUS: NEGOTIATING | Sector: Healthcare | client records, documents and so on | Deadline: 18d 19h |
|||||
| Ransomware | ****360.com id26821 View details | United States | Healthcare / Pharma | — | |
|
Status: STATUS: NEGOTIATING | Sector: healthcare logistics | Deadline: 18d 7h |
|||||
| Ransomware | ***wire id26820 View details | United States | Finance / Legal / Insurance | — | |
|
Status: STATUS: NEGOTIATING | Sector: LAW | Deadline: 18d 7h |
|||||
| Ransomware | for******a****ng id26819 View details | United States | Finance / Legal / Insurance | — | |
|
Status: STATUS: NEGOTIATING | Sector: Finance | Deadline: 18d 7h |
|||||
| Ransomware | pay*** id26818 View details | Egypt | Finance / Legal / Insurance | — | |
|
Status: STATUS: NEGOTIATING | Sector: Finance | Deadline: 18d 19h |
|||||
| Ransomware | Pappytech id26817 View details | India | IT | — | |
|
Status: STATUS: NEGOTIATING | Sector: retail | ├─ Main accounting software data directories (multiple financial years) ├─ Company-wise accounting datasets (separate numeric company instances) ├─ Archived accounting backups (ZIP and RAR files, mu... DATA SIZE: 22.82 GB | Deadline: 18d 7h |
|||||
| Ransomware | Federal University of Sergipe id25388 View details | Brazil | Education | — | |
|
Status: STATUS: NEGOTIATING | Sector: Education | financial records, students data, etc etc DATA SIZE: 150GB | Deadline: 3d 17h |
|||||
| Ransomware | Hytec South Africa id25343 View details | South Africa | Manufacturing / Engineering | — | |
|
Status: STATUS: NEGOTIATING | Sector: Engineering Solutions | All data exfiltrated including PII, employee information. | Deadline: 4d 15h |
|||||