Ransomware, Threat Intelligence

Nascent Vect RaaS operation examined

(Adobe Stock)

Infosecurity Magazine reports that organizations in Brazil and South Africa have already been compromised by the newly emergent Vect ransomware-as-a-service operation that has been seeking affiliates since December.

Vect has touted using C++-based ransomware with the advanced ChaCha20-Poly1305 AEAD encryption algorithm and SafeMode execution to stealthily target Windows, Linux, and VMware ESXi systems, according to an analysis from Halcyon. Such an RaaS operation is believed to have originated in the Commonwealth of Independent States after waiving the $250 entry fee for aspiring affiliates in the region. Vect has also been noted by Piranha Security to potentially be operated by experienced RaaS threat actors due to its use of custom multi-platform malware, sophisticated encryption methods, Monero for payments, TOX protocol for communications with affiliates, and TOR hidden services for infrastructure.

Organizations have been urged to defend themselves from Vect's double extortion intrusions by bolstering edge device security, implementing network segmentation, prioritizing Safe Mode and intermittent encryption detection, and adopting anti-ransomware solutions.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds