Tech »  Topic »  'VECT is being marketed as ransomware...but it functions as a data destruction tool': Experts warn this "broken" ransomware is now acting as a data wiper, so protect your files now

'VECT is being marketed as ransomware...but it functions as a data destruction tool': Experts warn this "broken" ransomware is now acting as a data wiper, so protect your files now


(Image credit: Pixabay)
  • A new ransomware variant was found to function as a destructive data wiper
  • Flawed nonce handling causes files larger than 128 KB to be permanently lost
  • Despite being marketed as RaaS, victims cannot recover data even if they pay

VECT 2.0, a relatively new ransomware variant that’s being offered for sale on dark web forums, is actually broken and works as a data wiper instead of an encryptor, researchers are warning.

In a new in-depth report, cybersecurity outfit Check Point explained that the problem is in the way VECT 2.0 handles “nonces” - random values needed to correctly encrypt, and later decrypt the data. Apparently, the malware splits large files into chunks, but instead of using new memory space for each nonce, it reuses the same, thus overwriting the previous one.

In other words, it loses the “keys” for most parts of the file as ...


Copyright of this story solely belongs to techradar.com . To see the full text click HERE