Vect Ransomware — Victims, Campaigns & Activity

Threat entity extracted from intelligence sources

Frequency
25
occurrences
First Seen
February 3, 2026
Last Seen
July 7, 2026

Vect is a ransomware_group tracked across 13 threat clusters and 25 intelligence report mentions on ThreatCluster. First observed February 3, 2026; most recent activity July 7, 2026.

Related Threat Clusters

  • Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise

    AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…

    30 articles · Updated April 1, 2026
  • Checkmarx Data Leak Linked to Supply-Chain Attack by TeamPCP

    Checkmarx, a software security firm, is investigating a significant data leak after its GitHub repository was compromised in a supply-chain attack on March 23, 2026. The attack, attributed to the TeamPCP cybercrime…

    12 articles · Updated April 27, 2026
  • Megalodon Campaign Infects Over 5,500 GitHub Repositories with Malware

    On May 18, 2026, an automated cyber campaign named Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attackers used forged identities and dummy accounts to inject malicious…

    7 articles · Updated May 26, 2026
  • Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages

    A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…

    697 articles · Updated April 29, 2026
  • Aerospace Phishing Campaign Uses AnyDesk for Remote Access and Data Exfiltration

    A spear-phishing campaign targets the aerospace sector, impersonating the Russian research institute VNIIR. Attackers use a spoof domain (vniir-avia.space) to deliver a password-protected RAR archive containing a…

    4 articles · Updated July 7, 2026
  • Vect 2.0 Ransomware Functions as Data Wiper, Not Encryptor

    The Vect 2.0 ransomware, emerging from a partnership with the TeamPCP group, has been found to irreversibly destroy files larger than 128 KB instead of encrypting them for ransom. This critical flaw, identified by Check…

    21 articles · Updated April 28, 2026
  • Vect and TeamPCP Form Alliance for Ransomware Operations

    In late March 2026, the Vect ransomware group partnered with TeamPCP, a credential theft specialist, to enhance their cybercriminal operations. This collaboration aims to leverage TeamPCP's extensive credential…

    8 articles · Updated July 2, 2026
  • TeamPCP Targets CI/CD Pipelines to Steal Developer Credentials

    TeamPCP, a financially motivated threat actor, has been conducting a campaign targeting software supply chains from March 19 to April 24, 2026. The group exploited trusted CI/CD and release workflows to steal sensitive…

    4 articles · Updated May 15, 2026
  • VECT 2.0 Ransomware Compromises File Recovery for Victims

    VECT 2.0 ransomware has emerged as a significant threat, leaving victims unable to recover files even with the attackers' decryptor. This ransomware employs a flawed design that discards nonces for earlier parts of…

    5 articles · Updated June 5, 2026
  • TeamPCP Supply Chain Attack Compromises Databricks Platform

    Databricks is investigating a potential security compromise linked to the TeamPCP supply chain attack. This incident follows a notification from International Cyber Digest, which indicated that Databricks was alerted…

    4 articles · Updated March 30, 2026

Recent Intelligence Reports

  • Thousands of MCP Servers Found Vulnerable to File Access and Injection Attacks — Gbhackers · July 7, 2026
  • Attackers Exfiltrate AnyDesk Configuration Data via Blat SMTP in Aerospace Phishing Campaign — Gbhackers · July 7, 2026
  • Industrialized ransomware alliance targets software supply chains and developers — Feeds.4Sysops · July 3, 2026
  • Warning Over “Industrialized” Cyber — Infosecurity-Magazine · July 3, 2026
  • Vect and TeamPCP partner for ransomware campaigns — Sophos · July 2, 2026
  • ‘Interpol’ emails spread custom ransomware with decryption key left inside — Feeds.Feedburner · July 2, 2026
  • Vect and TeamPCP partner for ransomware campaigns — News.Sophos · July 2, 2026
  • VECT 2.0 Ransomware Breaks Files Beyond Its Own Recovery — Gbhackers · June 5, 2026

CVSS v3.1 Breakdown