{"id":12474,"date":"2026-04-29T10:01:31","date_gmt":"2026-04-29T10:01:31","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/29\/new-vect-2-0-raas-operation-targets-windows-linux-and-esxi-systems\/"},"modified":"2026-04-29T10:01:31","modified_gmt":"2026-04-29T10:01:31","slug":"new-vect-2-0-raas-operation-targets-windows-linux-and-esxi-systems","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/29\/new-vect-2-0-raas-operation-targets-windows-linux-and-esxi-systems\/","title":{"rendered":"New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems"},"content":{"rendered":"<p>    New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new ransomware group known as Vect 2.0 has entered the global cyberthreat landscape, operating as a full Ransomware-as-a-Service (RaaS) platform that targets Windows, Linux, and VMware ESXi systems. <\/p>\n<p>The group first appeared in December 2025 and rapidly scaled its activity through February 2026, claiming at least 20 victims across multiple countries and critical industry sectors.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/08eb27b9-1285-4f6d-8d10-d1e2f1215315\/New-Vect-2.0-RaaS-Operation-Targets-Windows-Linux-and-ESXi-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYE6KSQINDE&amp;Signature=kr8qtV7Lc4NpiQgfU424WcANfOQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjECkaCXVzLWVhc3QtMSJHMEUCIQCCm5hi%2FKqPPYVduC7RUTMyyijeR%2F4C6sgzqwkm15wegwIgW5wovFwB9z7Dkil0cke8WXXxV87f1V9FBBh%2FMd%2F6gHAq%2FAQI8v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBWYMrjMyLeNaEz46SrQBKSL%2FDS3BFPOb9BBkTqgExZPEJO0ymzR5RZvOwvGPgy0aHzfBzJ3qAHwTEqHYF5I8tf8BGKw0vnOr1LFCAnF8b32sQj6QbBfq2wqGsFUaSLNF6fDBMVzZAVyIYhZ2Kujk7hXUsAwchT3%2BmkCn0kGD5pFfqmyADBLDXJxGg2lAhfSGGjNZMjYbaUecOE6PFNWpegASbMMdekpwbPpaLIkoyT7fJ9JU1JJNe6MV6wD5nQfn4DSkX6hxAsEqBVGVJNe%2FidWZ1UNQxK2exVSO3EMxz9qZRD53ZG99IubBi0FCeewvelctL6hMMwqPUZnzXnKBwLmMzvzVSCzI7uvykrmmDeh6Fr7ej9rpiF%2FBYd0n49NgZRdqNUjxnqvvS0FX3kqR1%2BNoHtV5IPICIYC6d1YmgSWdeD5GQgmeaX5bBQFcWEIZbllYRMjwmes20FpQRDdEgfNiqD7e0TZYhzqqYyTk7lOgduPiEUKVHWkz4Tjjm1Gzio4Y0CdId5lqK9oFJb5YbWaJUjLI4Np2OD8Im%2Fcs4Cevz8djGjU5lqm4vXfFZhTMdj7ANSN8u%2BkP64f%2F2MWIzue1p9YBe5FiASAFWts%2BeeOgmQSyJBOviVw9%2F907coV40EYziHCqa01W7ghgWr%2FRppwS4MkhaAvZA8ZqMn697spn8BusODOP81hVPn6%2BKvvK5FBC4EUcMjq6TBalNf5xzoxnkXjklHEI3kqz2IhALioFpLT4%2BoPhsI4vHlXySNMp24zUyuP5yVx3I%2FycHTUzzTAwevHYH4x8r5luMw%2B8GMwg4XHzwY6mAGBTJksLwHhw%2FeFgCYd%2FIGnaYDccXvYwjhjtQDxbjxfj8b6%2FnWwL9uRNxUmNAzvwt9PoNrSUg4MQ0f2KmZBIZRO8uxdsY9P5P6g9A6DlF502LhJb7iDBOyQ0U7Fs4kjqDV9lh48Y3oYSk%2BUH3nn%2BwVsWEW%2BVjCYDhwXlMhcN%2FK%2FSE6wyPFn1xmECbm%2BgpqtxJtz1OyEEPJUKQ%3D%3D&amp;Expires=1777454484\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Vect 2.0 is a rebranded evolution of the earlier \u201cVect\u201d operation, now powered by a custom-built C++ codebase that allows it to run on multiple operating systems with precision. <\/p>\n<p>The group operates on a triple-threat model it openly describes as \u201cExfiltration \/ Encryption \/ Extortion.\u201d <\/p>\n<p>This means it first steals sensitive data, then encrypts it to lock victims out, and finally threatens to publish the stolen files unless a ransom is paid. <\/p>\n<p>This layered approach leaves affected organizations in a difficult position, facing both operational disruption and the threat of public data exposure.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/08eb27b9-1285-4f6d-8d10-d1e2f1215315\/New-Vect-2.0-RaaS-Operation-Targets-Windows-Linux-and-ESXi-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYE6KSQINDE&amp;Signature=kr8qtV7Lc4NpiQgfU424WcANfOQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjECkaCXVzLWVhc3QtMSJHMEUCIQCCm5hi%2FKqPPYVduC7RUTMyyijeR%2F4C6sgzqwkm15wegwIgW5wovFwB9z7Dkil0cke8WXXxV87f1V9FBBh%2FMd%2F6gHAq%2FAQI8v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBWYMrjMyLeNaEz46SrQBKSL%2FDS3BFPOb9BBkTqgExZPEJO0ymzR5RZvOwvGPgy0aHzfBzJ3qAHwTEqHYF5I8tf8BGKw0vnOr1LFCAnF8b32sQj6QbBfq2wqGsFUaSLNF6fDBMVzZAVyIYhZ2Kujk7hXUsAwchT3%2BmkCn0kGD5pFfqmyADBLDXJxGg2lAhfSGGjNZMjYbaUecOE6PFNWpegASbMMdekpwbPpaLIkoyT7fJ9JU1JJNe6MV6wD5nQfn4DSkX6hxAsEqBVGVJNe%2FidWZ1UNQxK2exVSO3EMxz9qZRD53ZG99IubBi0FCeewvelctL6hMMwqPUZnzXnKBwLmMzvzVSCzI7uvykrmmDeh6Fr7ej9rpiF%2FBYd0n49NgZRdqNUjxnqvvS0FX3kqR1%2BNoHtV5IPICIYC6d1YmgSWdeD5GQgmeaX5bBQFcWEIZbllYRMjwmes20FpQRDdEgfNiqD7e0TZYhzqqYyTk7lOgduPiEUKVHWkz4Tjjm1Gzio4Y0CdId5lqK9oFJb5YbWaJUjLI4Np2OD8Im%2Fcs4Cevz8djGjU5lqm4vXfFZhTMdj7ANSN8u%2BkP64f%2F2MWIzue1p9YBe5FiASAFWts%2BeeOgmQSyJBOviVw9%2F907coV40EYziHCqa01W7ghgWr%2FRppwS4MkhaAvZA8ZqMn697spn8BusODOP81hVPn6%2BKvvK5FBC4EUcMjq6TBalNf5xzoxnkXjklHEI3kqz2IhALioFpLT4%2BoPhsI4vHlXySNMp24zUyuP5yVx3I%2FycHTUzzTAwevHYH4x8r5luMw%2B8GMwg4XHzwY6mAGBTJksLwHhw%2FeFgCYd%2FIGnaYDccXvYwjhjtQDxbjxfj8b6%2FnWwL9uRNxUmNAzvwt9PoNrSUg4MQ0f2KmZBIZRO8uxdsY9P5P6g9A6DlF502LhJb7iDBOyQ0U7Fs4kjqDV9lh48Y3oYSk%2BUH3nn%2BwVsWEW%2BVjCYDhwXlMhcN%2FK%2FSE6wyPFn1xmECbm%2BgpqtxJtz1OyEEPJUKQ%3D%3D&amp;Expires=1777454484\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Analysts and researchers at the <a href=\"https:\/\/www.dsci.in\/files\/content\/advisory\/2026\/threat-report-feb-2026.pdf\" id=\"https:\/\/www.dsci.in\/files\/content\/advisory\/2026\/threat-report-feb-2026.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Data Security Council of India (DSCI) tracked and identified the Vect 2.0 operation<\/a> through extensive dark web monitoring and ongoing threat intelligence analysis. <\/p>\n<p>Their findings revealed that the group\u2019s Data Leak Site (DLS) dashboard listed 20 active victim cases as of February 28, 2026, with 6 victims having their <a href=\"https:\/\/cybersecuritynews.com\/us-military-personnel-exposed\/\" id=\"473\" target=\"_blank\" rel=\"noreferrer noopener\">data leaked<\/a> publicly and 14 others still in active negotiation. <\/p>\n<p>Victim data was also distributed on well-known cybercrime platforms such as BreachForums, increasing pressure on targeted organizations to pay.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/08eb27b9-1285-4f6d-8d10-d1e2f1215315\/New-Vect-2.0-RaaS-Operation-Targets-Windows-Linux-and-ESXi-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYE6KSQINDE&amp;Signature=kr8qtV7Lc4NpiQgfU424WcANfOQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjECkaCXVzLWVhc3QtMSJHMEUCIQCCm5hi%2FKqPPYVduC7RUTMyyijeR%2F4C6sgzqwkm15wegwIgW5wovFwB9z7Dkil0cke8WXXxV87f1V9FBBh%2FMd%2F6gHAq%2FAQI8v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBWYMrjMyLeNaEz46SrQBKSL%2FDS3BFPOb9BBkTqgExZPEJO0ymzR5RZvOwvGPgy0aHzfBzJ3qAHwTEqHYF5I8tf8BGKw0vnOr1LFCAnF8b32sQj6QbBfq2wqGsFUaSLNF6fDBMVzZAVyIYhZ2Kujk7hXUsAwchT3%2BmkCn0kGD5pFfqmyADBLDXJxGg2lAhfSGGjNZMjYbaUecOE6PFNWpegASbMMdekpwbPpaLIkoyT7fJ9JU1JJNe6MV6wD5nQfn4DSkX6hxAsEqBVGVJNe%2FidWZ1UNQxK2exVSO3EMxz9qZRD53ZG99IubBi0FCeewvelctL6hMMwqPUZnzXnKBwLmMzvzVSCzI7uvykrmmDeh6Fr7ej9rpiF%2FBYd0n49NgZRdqNUjxnqvvS0FX3kqR1%2BNoHtV5IPICIYC6d1YmgSWdeD5GQgmeaX5bBQFcWEIZbllYRMjwmes20FpQRDdEgfNiqD7e0TZYhzqqYyTk7lOgduPiEUKVHWkz4Tjjm1Gzio4Y0CdId5lqK9oFJb5YbWaJUjLI4Np2OD8Im%2Fcs4Cevz8djGjU5lqm4vXfFZhTMdj7ANSN8u%2BkP64f%2F2MWIzue1p9YBe5FiASAFWts%2BeeOgmQSyJBOviVw9%2F907coV40EYziHCqa01W7ghgWr%2FRppwS4MkhaAvZA8ZqMn697spn8BusODOP81hVPn6%2BKvvK5FBC4EUcMjq6TBalNf5xzoxnkXjklHEI3kqz2IhALioFpLT4%2BoPhsI4vHlXySNMp24zUyuP5yVx3I%2FycHTUzzTAwevHYH4x8r5luMw%2B8GMwg4XHzwY6mAGBTJksLwHhw%2FeFgCYd%2FIGnaYDccXvYwjhjtQDxbjxfj8b6%2FnWwL9uRNxUmNAzvwt9PoNrSUg4MQ0f2KmZBIZRO8uxdsY9P5P6g9A6DlF502LhJb7iDBOyQ0U7Fs4kjqDV9lh48Y3oYSk%2BUH3nn%2BwVsWEW%2BVjCYDhwXlMhcN%2FK%2FSE6wyPFn1xmECbm%2BgpqtxJtz1OyEEPJUKQ%3D%3D&amp;Expires=1777454484\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The most targeted countries include Brazil and the United States, each with four victims, followed by India with three. Other affected nations include South Africa, Egypt, Spain, Colombia, Italy, and Namibia. <\/p>\n<p>The sectors impacted most are manufacturing, education, healthcare, and technology, industries that hold large volumes of sensitive data and depend on continuous availability to keep daily operations running.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/08eb27b9-1285-4f6d-8d10-d1e2f1215315\/New-Vect-2.0-RaaS-Operation-Targets-Windows-Linux-and-ESXi-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYE6KSQINDE&amp;Signature=kr8qtV7Lc4NpiQgfU424WcANfOQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjECkaCXVzLWVhc3QtMSJHMEUCIQCCm5hi%2FKqPPYVduC7RUTMyyijeR%2F4C6sgzqwkm15wegwIgW5wovFwB9z7Dkil0cke8WXXxV87f1V9FBBh%2FMd%2F6gHAq%2FAQI8v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBWYMrjMyLeNaEz46SrQBKSL%2FDS3BFPOb9BBkTqgExZPEJO0ymzR5RZvOwvGPgy0aHzfBzJ3qAHwTEqHYF5I8tf8BGKw0vnOr1LFCAnF8b32sQj6QbBfq2wqGsFUaSLNF6fDBMVzZAVyIYhZ2Kujk7hXUsAwchT3%2BmkCn0kGD5pFfqmyADBLDXJxGg2lAhfSGGjNZMjYbaUecOE6PFNWpegASbMMdekpwbPpaLIkoyT7fJ9JU1JJNe6MV6wD5nQfn4DSkX6hxAsEqBVGVJNe%2FidWZ1UNQxK2exVSO3EMxz9qZRD53ZG99IubBi0FCeewvelctL6hMMwqPUZnzXnKBwLmMzvzVSCzI7uvykrmmDeh6Fr7ej9rpiF%2FBYd0n49NgZRdqNUjxnqvvS0FX3kqR1%2BNoHtV5IPICIYC6d1YmgSWdeD5GQgmeaX5bBQFcWEIZbllYRMjwmes20FpQRDdEgfNiqD7e0TZYhzqqYyTk7lOgduPiEUKVHWkz4Tjjm1Gzio4Y0CdId5lqK9oFJb5YbWaJUjLI4Np2OD8Im%2Fcs4Cevz8djGjU5lqm4vXfFZhTMdj7ANSN8u%2BkP64f%2F2MWIzue1p9YBe5FiASAFWts%2BeeOgmQSyJBOviVw9%2F907coV40EYziHCqa01W7ghgWr%2FRppwS4MkhaAvZA8ZqMn697spn8BusODOP81hVPn6%2BKvvK5FBC4EUcMjq6TBalNf5xzoxnkXjklHEI3kqz2IhALioFpLT4%2BoPhsI4vHlXySNMp24zUyuP5yVx3I%2FycHTUzzTAwevHYH4x8r5luMw%2B8GMwg4XHzwY6mAGBTJksLwHhw%2FeFgCYd%2FIGnaYDccXvYwjhjtQDxbjxfj8b6%2FnWwL9uRNxUmNAzvwt9PoNrSUg4MQ0f2KmZBIZRO8uxdsY9P5P6g9A6DlF502LhJb7iDBOyQ0U7Fs4kjqDV9lh48Y3oYSk%2BUH3nn%2BwVsWEW%2BVjCYDhwXlMhcN%2FK%2FSE6wyPFn1xmECbm%2BgpqtxJtz1OyEEPJUKQ%3D%3D&amp;Expires=1777454484\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The group runs its entire infrastructure through TOR hidden services and accepts ransom payments only in Monero (XMR), a privacy-focused cryptocurrency that makes financial tracing difficult. <\/p>\n<p>All affiliate and operator communications use the TOX protocol and a proprietary tool called \u201cVect Secure Chat.\u201d <\/p>\n<p>New affiliates are charged a $250 USD entry fee in Monero, though this fee is waived for applicants from Commonwealth of Independent States (CIS) countries, a detail that points toward operators likely based in Russia or Belarus.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/08eb27b9-1285-4f6d-8d10-d1e2f1215315\/New-Vect-2.0-RaaS-Operation-Targets-Windows-Linux-and-ESXi-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYE6KSQINDE&amp;Signature=kr8qtV7Lc4NpiQgfU424WcANfOQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjECkaCXVzLWVhc3QtMSJHMEUCIQCCm5hi%2FKqPPYVduC7RUTMyyijeR%2F4C6sgzqwkm15wegwIgW5wovFwB9z7Dkil0cke8WXXxV87f1V9FBBh%2FMd%2F6gHAq%2FAQI8v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBWYMrjMyLeNaEz46SrQBKSL%2FDS3BFPOb9BBkTqgExZPEJO0ymzR5RZvOwvGPgy0aHzfBzJ3qAHwTEqHYF5I8tf8BGKw0vnOr1LFCAnF8b32sQj6QbBfq2wqGsFUaSLNF6fDBMVzZAVyIYhZ2Kujk7hXUsAwchT3%2BmkCn0kGD5pFfqmyADBLDXJxGg2lAhfSGGjNZMjYbaUecOE6PFNWpegASbMMdekpwbPpaLIkoyT7fJ9JU1JJNe6MV6wD5nQfn4DSkX6hxAsEqBVGVJNe%2FidWZ1UNQxK2exVSO3EMxz9qZRD53ZG99IubBi0FCeewvelctL6hMMwqPUZnzXnKBwLmMzvzVSCzI7uvykrmmDeh6Fr7ej9rpiF%2FBYd0n49NgZRdqNUjxnqvvS0FX3kqR1%2BNoHtV5IPICIYC6d1YmgSWdeD5GQgmeaX5bBQFcWEIZbllYRMjwmes20FpQRDdEgfNiqD7e0TZYhzqqYyTk7lOgduPiEUKVHWkz4Tjjm1Gzio4Y0CdId5lqK9oFJb5YbWaJUjLI4Np2OD8Im%2Fcs4Cevz8djGjU5lqm4vXfFZhTMdj7ANSN8u%2BkP64f%2F2MWIzue1p9YBe5FiASAFWts%2BeeOgmQSyJBOviVw9%2F907coV40EYziHCqa01W7ghgWr%2FRppwS4MkhaAvZA8ZqMn697spn8BusODOP81hVPn6%2BKvvK5FBC4EUcMjq6TBalNf5xzoxnkXjklHEI3kqz2IhALioFpLT4%2BoPhsI4vHlXySNMp24zUyuP5yVx3I%2FycHTUzzTAwevHYH4x8r5luMw%2B8GMwg4XHzwY6mAGBTJksLwHhw%2FeFgCYd%2FIGnaYDccXvYwjhjtQDxbjxfj8b6%2FnWwL9uRNxUmNAzvwt9PoNrSUg4MQ0f2KmZBIZRO8uxdsY9P5P6g9A6DlF502LhJb7iDBOyQ0U7Fs4kjqDV9lh48Y3oYSk%2BUH3nn%2BwVsWEW%2BVjCYDhwXlMhcN%2FK%2FSE6wyPFn1xmECbm%2BgpqtxJtz1OyEEPJUKQ%3D%3D&amp;Expires=1777454484\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"multi-platform-infection-mechanism-and-defense-eva\"><strong>Multi-Platform Infection Mechanism and Defense Evasion<\/strong><\/h2>\n<p>Vect 2.0 deploys separate, purpose-built executables for each targeted platform. The Windows payload is a file named \u201csvc_host_update.exe,\u201d crafted to blend in with legitimate Windows system processes. <\/p>\n<p>For Linux and VMware ESXi environments, the group deploys a dedicated binary called \u201cenc_esxi.elf.\u201d Once executed, the ransomware encrypts files and appends the \u201c.vect\u201d extension. <\/p>\n<p>Victims then find ransom notes titled \u201cVECT_RECOVERY_GUIDE.txt\u201d or \u201cREADME_VECT.html\u201d directing them to a negotiation portal through a TOR-based link.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiVKiYvrRJGTsIa77AhyS_ESGsHXBlM-hi8_5mWl6wooXON7nlgejn3gbxoJlVOEnMgTJmYfsoZqU53OnaS7gzoJnNvEvi9LZnw46-6qlka-omoC1n04I_NiU47ShyphenhyphenHjIhOJt2WhfiLy8fwO4xT4zNkqL-9NZadbTRd7gYTBrQdp2lMyT8x9xXUae3DT4Y\/s16000\/Vect%25202.0%2520Ransom%2520Note%2520%28Source%2520-%2520DSCI%29.webp?ssl=1\" alt=\"Vect 2.0 Ransom Note (Source - DSCI)\"><figcaption class=\"wp-element-caption\">Vect 2.0 Ransom Note (Source \u2013 DSCI)<\/figcaption><\/figure>\n<\/div>\n<p>To avoid detection, Vect 2.0 uses a Safe Mode Boot technique (MITRE ATT&amp;CK T1562.009), forcing the compromised system to restart in Safe Mode where most endpoint security tools remain inactive. <\/p>\n<p>This gives the ransomware a clear window to encrypt data without interference. Initial access is typically gained through stolen or weak credentials (T1078), exposed RDP or VPN services (T1133), or phishing emails (T1566). <\/p>\n<p>After gaining entry, the group moves laterally across the network through SMB shares and WinRM, collects data from local systems and shared drives, and then exfiltrates it through TOR-encrypted channels before triggering encryption.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/08eb27b9-1285-4f6d-8d10-d1e2f1215315\/New-Vect-2.0-RaaS-Operation-Targets-Windows-Linux-and-ESXi-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYE6KSQINDE&amp;Signature=kr8qtV7Lc4NpiQgfU424WcANfOQ%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjECkaCXVzLWVhc3QtMSJHMEUCIQCCm5hi%2FKqPPYVduC7RUTMyyijeR%2F4C6sgzqwkm15wegwIgW5wovFwB9z7Dkil0cke8WXXxV87f1V9FBBh%2FMd%2F6gHAq%2FAQI8v%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDBWYMrjMyLeNaEz46SrQBKSL%2FDS3BFPOb9BBkTqgExZPEJO0ymzR5RZvOwvGPgy0aHzfBzJ3qAHwTEqHYF5I8tf8BGKw0vnOr1LFCAnF8b32sQj6QbBfq2wqGsFUaSLNF6fDBMVzZAVyIYhZ2Kujk7hXUsAwchT3%2BmkCn0kGD5pFfqmyADBLDXJxGg2lAhfSGGjNZMjYbaUecOE6PFNWpegASbMMdekpwbPpaLIkoyT7fJ9JU1JJNe6MV6wD5nQfn4DSkX6hxAsEqBVGVJNe%2FidWZ1UNQxK2exVSO3EMxz9qZRD53ZG99IubBi0FCeewvelctL6hMMwqPUZnzXnKBwLmMzvzVSCzI7uvykrmmDeh6Fr7ej9rpiF%2FBYd0n49NgZRdqNUjxnqvvS0FX3kqR1%2BNoHtV5IPICIYC6d1YmgSWdeD5GQgmeaX5bBQFcWEIZbllYRMjwmes20FpQRDdEgfNiqD7e0TZYhzqqYyTk7lOgduPiEUKVHWkz4Tjjm1Gzio4Y0CdId5lqK9oFJb5YbWaJUjLI4Np2OD8Im%2Fcs4Cevz8djGjU5lqm4vXfFZhTMdj7ANSN8u%2BkP64f%2F2MWIzue1p9YBe5FiASAFWts%2BeeOgmQSyJBOviVw9%2F907coV40EYziHCqa01W7ghgWr%2FRppwS4MkhaAvZA8ZqMn697spn8BusODOP81hVPn6%2BKvvK5FBC4EUcMjq6TBalNf5xzoxnkXjklHEI3kqz2IhALioFpLT4%2BoPhsI4vHlXySNMp24zUyuP5yVx3I%2FycHTUzzTAwevHYH4x8r5luMw%2B8GMwg4XHzwY6mAGBTJksLwHhw%2FeFgCYd%2FIGnaYDccXvYwjhjtQDxbjxfj8b6%2FnWwL9uRNxUmNAzvwt9PoNrSUg4MQ0f2KmZBIZRO8uxdsY9P5P6g9A6DlF502LhJb7iDBOyQ0U7Fs4kjqDV9lh48Y3oYSk%2BUH3nn%2BwVsWEW%2BVjCYDhwXlMhcN%2FK%2FSE6wyPFn1xmECbm%2BgpqtxJtz1OyEEPJUKQ%3D%3D&amp;Expires=1777454484\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Organizations can reduce risk by blocking known Vect 2.0 IP addresses such as 158.94.210.11 (Port 8000) and restricting outbound TOR traffic at the network perimeter. <\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/security-teams-shrink-as-automation-rises\/\" id=\"100650\" target=\"_blank\" rel=\"noreferrer noopener\">Security teams<\/a> should set up alerts for bcdedit command activity and any unexpected Safe Mode reboots, as these are signs of an active evasion attempt. <\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/why-multi-factor-authentication-is-no-longer-optional-in-2024\/\" id=\"83847\" target=\"_blank\" rel=\"noreferrer noopener\">Multi-factor authentication (MFA)<\/a> must be enforced on all remote access services, including RDP, VPN, and ESXi interfaces. <\/p>\n<p>Following the 3-2-1 backup rule, keeping three data copies with one stored offline, ensures recovery without paying a ransom. Regular phishing awareness training for all employees remains equally important.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-vect-2-0-raas-operation-targets\/\">New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-vect-2-0-raas-operation-targets\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems A new ransomware group known as Vect 2.0 has entered the global cyberthreat landscape, operating as a full Ransomware-as-a-Service (RaaS) platform that targets Windows, Linux, and VMware ESXi systems. The group first appeared in December 2025 and rapidly scaled its activity through February 2026, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12474","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12474"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12474"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12474\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}