logo

SEXi ransomware rebrands to APT INC, continues VMware ESXi attacks

ID: 2ae2b0b1-acf9-542f-8ca4-dc3d4ebea895

STIX ID: report--2ae2b0b1-acf9-542f-8ca4-dc3d4ebea895

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-07-15

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

The SEXi ransomware operation, now rebranding as APT INC, is actively using leaked Babuk (ESXi-focused) and LockBit 3 (Windows) encryptors to compromise VMware ESXi servers and Windows systems, encrypt virtual machine disks and backups, and extort victims with varying ransom demands; multiple victims have reported incidents and no free recovery exists due to the secure encryptors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.