Vect Interview

Vect Interview

Jul 04, 2026

Vect first appeared on the Russian forum ReHub in late December 2025. The group’s 'Partner Program' recruited CIS (Commonwealth of Independent States) actors with free entry while charging non-CIS affiliates $250 for access.

imageHi, thanks for taking the time to speak with Inside Darknet. For people who don't know you yet - who is Vect, and what do you do?

Vect is an RaaS group built around affiliate performance. We supply the full toolkit, infrastructure, encryption, leak site, and payment support so affiliates can maximize their hauls without operational friction. Better payouts for affiliates directly translate to better scaling for us, so it’s a win-win by design.

Your locker was broken earlier this year - any file over 131 KB got permanently destroyed instead of encrypted. You told me that this came from another developer working with you. Can you share what happened and have you fixed it?

That incident stemmed from a deployment oversight by a third-party developer collaborating with us. He shipped an untested patch that triggered a boundary error, causing files larger than 131KB to be deleted instead of encrypted. It also introduced a bottleneck that slowed encryption speeds by roughly 10x.

We caught the issue after a the reputation loss already happened, since that we discontinued, The rep took a hit early on, but we’ve since stabilized it. The underlying architecture is solid though, we may even release the core logic later this year so another team can build on it and give affiliates an even more efficient tool.

In January 2026, Researchers noted you were sourcing compromised Fortinet accounts on a cybercrime forum. Was that your main initial access vector at the time, aside from operating your RaaS?

As the spokesperson, I mainly handle marketing and brand positioning, so I’ll keep this high-level.

At Vect, we never pin our success to a single entry point. Fortinet credentials are definitely in rotation, they’re excellent for lateral movement and network pivoting, but they’re just one of the initial access vector we use. Our operators use anything that can possibly lead to a ransom attack: RDP accesses, leaked VPNs, zero-days, targeted phishing, even supply-chain vectors. A mature ransomware operation doesn’t rely on one door, it keeps multiple breaches open at all times.

You were one of the three groups involved in the big supply chain earlier this year. Was this your first operation at this scale?

If you mean Canisterworm and Shai Hulud? yes, their operations set a new benchmark in 2026, likely the largest of the decade so far.

For me personally however, large-scale distribution isn’t new. I’ve overseen campaigns that reached well beyond 7 figures across multiple sectors and regions. We treat supply chain as one vector among many, and when we align it with our affiliate network or hit targeted enterprise stacks, the payout potential scales exponentially.

And in these breaches, what was your role was there?

I was just the spokesperson, the marketing and branding guy.

You've reportedly have had issues with insiders within your own group. Perhaps you can share how that happened, and if have they been removed?

We did experience some insider challenges, like any other ransomware group (conti-blackbasta-lockbit-babuk-REvil-darkside) obviously these insiders are common and partially harmless, nothing sensitive was being shared between operators because we operate knowing that we will be insided or already insided one day, but following the decryption incident, we chose to fully disband the original operator team rather than continue operating.

The bug cost us significant revenue and victim trust, so we reset. The old Vect disbanded.

These partnerships then extended to BreachForums, where every registered member received a personal Vect affiliate key. What was your plan, and is it still ongoing?

That BreachForums campaign was my strategic fingerprint.

I realized we could out-earn traditional RaaS ticket sales by weaponizing an entire community instead of chasing individual buyers. By issuing free, personalized keys to every registered member, we lowered the barrier to entry and shifted dormant data extortionists into active ransomware operators. They bring the targets and the lateral grind; we provide the encryptor, leak site, and payout routing. It turns their scattered efforts into a synchronized revenue engine.

The campaign is dead after the disband, but I can guarantee you that it will happen again if not by me, it will be by an other ransomware group learning from my marketing tactics, you can see now that dragonforce and the gentleman ransomware groups have already started following what I did.

With all this, is Vect still operating and going to operate a RaaS in the future?

The simple answer is no, even I know that everything comes to an end at some point

Someone recently asked me, how cybercrime groups choose their targets. Perhaps you can share a little bit of your insights on this?

We chose targets based on geolocation and revenue and most importantly insurance, if a company has insurance it's almost guaranteed they will pay

Are you ever worried about law enforcement catching up to you?

I assume everyone who's living a high stakes life is living in constant fear. everyone is worried about law enforcement catching up to them, but the money we make is worth this paranoia.

And one final question: if you could give one message to the public, what would it be?

My message to the public would be: your skills does not matter if you want to become successful, all you need to have is some brain and courage.

Enjoy this post?

Buy Inside Darknet a coffee

More from Inside Darknet