Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
AboutDFIR

AboutDFIR Vendor Cyber Rating & Cyber Score

aboutdfir.com

The best DFIR resource on the planet ran by those who work everyday in DFIR.


AboutDFIR A.I CyberSecurity Scoring

AboutDFIR
Company Information
Website:https://aboutdfir.com/
Employees number:1
Number of followers:988
NAICS:541514
Industry Type:Computer and Network Security
Homepage:aboutdfir.com
AboutDFIR Risk Score (AI oriented)
Between 700 and 749
logo
AboutDFIRComputer and Network Security
Updated:
29/04/2026
734/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
AboutDFIR Global Score (TPRM)
xxxx
logo
AboutDFIRComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

AboutDFIR
AboutDFIRModerate
Current Score
734Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
734Before Incident
MAY 2026
734Before Incident
APRIL 2026
734Before Incident
MARCH 2026
733Before Incident
FEBRUARY 2026
733Before Incident
JANUARY 2026
732Before Incident
DECEMBER 2025
731Before Incident
NOVEMBER 2025
731Before Incident
OCTOBER 2025
747Before Incident
Cyber Attack
01 Oct 2025AboutDFIR
BreachForums: VECT 2.0 Ransomware Wipes Large Files Across Windows, Linux & ESXi

VECT 2.0 Ransomware Unmasked as a Cross-Platform Data Wiper with Unrecoverable Encryption Flaws

730After Incident
CRITICAL-17
ABO1777458252
VECT 2.0 Ransomware Unmasked as a Cross-Platform Data Wiper with Unrecoverable Encryption Flaws Researchers at Check Point Research (CPR) have exposed VECT 2.0 a ransomware strain marketed as a recoverable encryption tool as a cross-platform data wiper that permanently destroys enterprise files. Unlike traditional ransomware, VECT 2.0’s flawed encryption routine renders most critical data mathematically unrecoverable, even for the attackers, making it a destructive threat rather than a viable extortion tool. ### How VECT 2.0 Operates VECT 2.0 targets Windows, Linux, and VMware ESXi systems, processing files larger than 128 KB in four separate chunks using ChaCha20-IETF encryption. However, the malware discards the first three encryption nonces required for decryption without storing them, leaving 75% of each large file irretrievably corrupted. Only the last nonce is appended to the file, making recovery impossible for files exceeding the threshold. This design flaw affects nearly all enterprise file types, including: - Virtual machine disk images - Databases - Documents and archives - Backups ### Technical Flaws and Misleading Marketing Despite VECT’s claims of using ChaCha20-Poly1305 AEAD encryption, CPR found it relies on raw ChaCha20-IETF without authentication tags, meaning there is no integrity protection only ciphertext and a single nonce. The malware also includes unused "encryption speed" flags (e.g., `--fast`, `--medium`, `--secure`), which have no functional impact, exposing a gap between its marketing and actual implementation. Additional issues include: - Over-threaded encryption, degrading performance despite aggressive CPU-based scaling. - Unreachable anti-analysis code and ineffective string obfuscation. - Hardcoded thresholds (128 KB file size, 32 KB chunks) that remain unchanged regardless of operator settings. ### RaaS Model and Affiliate Expansion VECT operates as a Ransomware-as-a-Service (RaaS) program, first advertised on a Russian-language forum in late 2025 and linked to at least two victims by early 2026. The group has since partnered with BreachForums, offering all registered users affiliate access to its ransomware panel, negotiation platform, and leak site. It has also collaborated with TeamPCP, a supply-chain threat actor. Despite its professional branding, VECT’s low victim count and technical shortcomings suggest weak engineering behind the operation. ### Impact: Permanent Data Loss Security experts warn that paying the ransom will not restore corrupted files, as the encryption design ensures permanent destruction of most enterprise data. Organizations affected by VECT 2.0 should treat the incident as a data-wiping attack rather than a recoverable ransomware case. The flaw has existed since the malware’s earliest observed deployments and remains unpatched.
INCIDENT DETAILS -
TYPE
Ransomware (Data Wiper)
MOTIVATION
Financial gain (extortion), though encryption flaws render it ineffective; potential destructive intent
IMPACT
Data Compromised: Permanent destruction of enterprise files (75% of large files irrecoverable)Systems Affected: Windows, Linux, VMware ESXiOperational Impact: Permanent data loss for critical files (VM disk images, databases, backups, documents)Brand Reputation Impact: Potential reputational damage due to permanent data loss
DATA BREACH
Type Of Data Compromised: Enterprise files (VM disk images, databases, documents, backups, archives)Sensitivity Of Data: High (critical enterprise data)Data Encryption: ChaCha20-IETF (flawed, nonces discarded)Virtual machine disk imagesDatabasesDocumentsArchivesBackups
SEPTEMBER 2025
747Before Incident
AUGUST 2025
747Before Incident
JULY 2025
747Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for AboutDFIR ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in May 2026 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in April 2026 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in March 2026 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in February 2026 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in January 2026 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in December 2025 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in November 2025 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in October 2025 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in September 2025 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in August 2025 ?
?
What was AboutDFIR's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on AboutDFIR's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with AboutDFIR ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view AboutDFIR's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?