‘VECT is being marketed as ransomware…but it works as a data destruction tool’: Experts warn this ‘broken’ ransomware now acts as a data wipe, so protect your files now


  • A new ransomware variant was found to act as a destructive data wipe
  • Improper handling results in permanent loss of files larger than 128 KB
  • Despite being marketed as RaaS, victims cannot recover data even if they pay

VECT 2.0, a relatively new ransomware variant offered for sale on dark web forums, is actually broken and acts as a data wipe instead of an encryption one, researchers warn.

In a new in-depth report, cybersecurity outfit Check Point explained that the problem is the way VECT 2.0 handles “nonces” — random values ​​needed to properly encrypt and later decrypt the data. Apparently, the malware splits large files into chunks, but instead of using new memory space for each nonce, it reuses the same one, thus overwriting the previous one.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top