SEXi Ransomware Desires VMware Hypervisors in Ongoing Campaign
ID: c0fdafc6-c480-56cb-881e-49bb9cbf1649
STIX ID: report--c0fdafc6-c480-56cb-881e-49bb9cbf1649
Feed Name: Dark Reading
Date Published: 2024-04-04
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
A fresh Babuk-derived ransomware strain branded "SEXi" is actively targeting VMware ESXi servers—confirmed in an attack on Chilean host IxMetro PowerHost—using variants (Limpopo, Socotra, Formosa) deployed across multiple Latin American countries; attackers use the .SEXi extension, deliver binaries such as LIMPOPOx32.bin, demand a $140M ransom, and instruct victims to contact them via the privacy-focused Session messaging app.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
