logo

SEXi Ransomware Rebrands as 'APT Inc.,' Keeps Old Methods

ID: bba88882-c6e2-5496-b534-28e6a8bdc8a8

STIX ID: report--bba88882-c6e2-5496-b534-28e6a8bdc8a8

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-07-15

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

SEXi ransomware operators, now calling themselves “APT Inc.”, have been carrying out active ransomware attacks since February (rebranded in June), using leaked Babuk encryptors to target VMware ESXi and leaked LockBit 3 encryptors for Windows servers; victims report ransom notes and demands ranging from thousands to millions of dollars, and no free recovery/decryptor currently exists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.