logo

SEXi Ransomware Desires VMware Hypervisors in Ongoing Campaign

ID: c0fdafc6-c480-56cb-881e-49bb9cbf1649

STIX ID: report--c0fdafc6-c480-56cb-881e-49bb9cbf1649

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-04-04

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

A fresh Babuk-derived ransomware strain branded "SEXi" is actively targeting VMware ESXi servers—confirmed in an attack on Chilean host IxMetro PowerHost—using variants (Limpopo, Socotra, Formosa) deployed across multiple Latin American countries; attackers use the .SEXi extension, deliver binaries such as LIMPOPOx32.bin, demand a $140M ransom, and instruct victims to contact them via the privacy-focused Session messaging app.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.