SEXi Ransomware Rebrands as 'APT Inc.,' Keeps Old Methods
ID: bba88882-c6e2-5496-b534-28e6a8bdc8a8
STIX ID: report--bba88882-c6e2-5496-b534-28e6a8bdc8a8
Feed Name: Dark Reading
Threat Score
SEXi ransomware operators, now calling themselves “APT Inc.”, have been carrying out active ransomware attacks since February (rebranded in June), using leaked Babuk encryptors to target VMware ESXi and leaked LockBit 3 encryptors for Windows servers; victims report ransom notes and demands ranging from thousands to millions of dollars, and no free recovery/decryptor currently exists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
