Hosting firm's VMware ESXi servers hit by new SEXi ransomware
ID: 4c427ea3-ec8b-5acb-a43c-8bb40281e6e6
STIX ID: report--4c427ea3-ec8b-5acb-a43c-8bb40281e6e6
Feed Name: Bleeping Computer
Threat Score
Chilean hosting provider PowerHost (IxMetro) suffered a ransomware attack by a newly observed group calling itself “SEXi” that encrypted VMware ESXi virtual machines and backups, disrupting customer VPS services; ransom notes and variants (SOCOTRA, FORMOSA, LIMPOPO) have been observed and some encryptors appear derived from leaked Babuk and LockBit 3.0 code, with Windows samples claiming data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
