logo

Hosting firm's VMware ESXi servers hit by new SEXi ransomware

ID: 4c427ea3-ec8b-5acb-a43c-8bb40281e6e6

STIX ID: report--4c427ea3-ec8b-5acb-a43c-8bb40281e6e6

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-04-03

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Chilean hosting provider PowerHost (IxMetro) suffered a ransomware attack by a newly observed group calling itself “SEXi” that encrypted VMware ESXi virtual machines and backups, disrupting customer VPS services; ransom notes and variants (SOCOTRA, FORMOSA, LIMPOPO) have been observed and some encryptors appear derived from leaked Babuk and LockBit 3.0 code, with Windows samples claiming data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.