“VECT is marketed as ransomware… but it functions as a data destruction tool”: Experts warn this ‘broken’ ransomware now acts as a data eraser, so protect your files now


  • New ransomware variant found to work as destructive data eraser
  • Faulty nonce management results in permanent loss of files larger than 128 KB
  • Although it is marketed as RaaS, victims cannot recover their data even if they pay

VECT 2.0, a relatively new ransomware variant offered for sale on dark web forums, is actually broken and functions as a data eraser instead of an encrypter, researchers warn.

In an in-depth new report, cybersecurity firm Check Point explained that the problem lies in how VECT 2.0 handles “nonces” – the random values ​​needed to properly encrypt and then decrypt data. Apparently, the malware splits large files into pieces, but instead of using new memory space for each occasional case, it reuses it, thereby overwriting the previous one.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top