‘VECT is being marketed as ransomware…but it functions as a data destruction tool’: Experts warn this “broken” ransomware is now acting as a data wiper, so protect your files now



  • A new ransomware variant was found to function as a destructive data wiper
  • Flawed nonce handling causes files larger than 128 KB to be permanently lost
  • Despite being marketed as RaaS, victims cannot recover data even if they pay

VECT 2.0, a relatively new ransomware variant that’s being offered for sale on dark web forums, is actually broken and works as a data wiper instead of an encryptor, researchers are warning.

In a new in-depth report, cybersecurity outfit Check Point explained that the problem is in the way VECT 2.0 handles “nonces” – random values needed to correctly encrypt, and later decrypt the data. Apparently, the malware splits large files into chunks, but instead of using new memory space for each nonce, it reuses the same, thus overwriting the previous one.

https://cdn.mos.cms.futurecdn.net/cJtFPyQYv7tobzbzvGKgSX-1916-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img