VECT: Ransomware by design, Wiper by accident
2026-04-28T20:52:26Z•4baf1422e2c9441c6cf0277d159edb5c12953b723936f9f310ebbccdca14c295
AI-assisted-malwareCVE-2026-3502ChatGPTDFIRHandala HackIranian-actorsOAuthRaaSSystemBCTeamPCPThe GentlemenTrueConfVECTVoidLinkdata-breachdata-leakageransomwaresupply-chaintoken-compromisewiperzero-day
What happened
Check Point Research collection (Mar–Apr 2026) covering multiple high‑impact threats: the emergence of VECT RaaS (ransomware-by-design that has exhibited wiper-like behavior) and its partnership with TeamPCP; weekly Threat Intelligence digests describing major breaches and incidents (including Vercel/Context.ai OAuth token misuse, Booking.com data exposure, EU Commission/Trivy supply‑chain compromise, and others); DFIR analysis of The Gentlemen RaaS and SystemBC proxy tooling; Operation TrueChaos — active exploitation of a TrueConf zero‑day (CVE-2026-3502, CVSS 7.8) against Southeast Asian gov
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- checkpoint_research
- Record identifier
- 4baf1422e2c9441c6cf0277d159edb5c12953b723936f9f310ebbccdca14c295
- Enrichment time
- 2026-04-28T20:52:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.