Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: SOCOTRA, FORMOSA, CVE-2025-55182, Project Spy, Cridex, U2DiskWatch, similar to Sliver, Cobalt Strike, consists of multiple components, control module, NoFive, Plat1, keygroup777, TA558, CVE-2025-53770, CVE-2025-53771, CVE-2025-32433, OTP's SSH implementation, CVE-2025-22224, CVE-2025-22225, LockBit 3.0, CVE-2025-23006, CVE-2024-55956, 419, advanced fee scam, to the economic, BokBot

Description

SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines and backups, causing significant disruptions to services. The group's name is a play on the word "ESXi," indicating a deliberate focus on these systems. SEXi has been linked to other ransomware variants based on the Babuk source code.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Telecommunications
Manufacturing
Healthcare
Education
Transportation
Energy
Critical infrastructure
Media
Retail
Information technology
Aerospace
Hospitality
Non profit
Mining
Pharmaceutical
Aviation
Construction
Maritime
Chemical
Legal services
Nuclear
Gaming
Entertainment
Food agriculture

Targeted Countries / Regions

US
RU
CN
UA
BR
KR
GB
PL
IN
AU
MX
ES
CA
JP
IT
DE
TR
IL
SY
TW
SA
IR
FR
VN
SG
KP
AE
NL
AZ
KZ

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 7 URL 7 Domain 6

References

  1. www.cybereason.com — Cited by web research for: CVE-2025-55182
  2. attack.mitre.org — Cited by web research for: Project Spy
  3. www.kaspersky.com — Cited by web research for: keygroup777
  4. www.group-ib.com — Cited by web research for: PowerShell
  5. www.huntress.com — Cited by web research for: systemd
  6. pmc.ncbi.nlm.nih.gov — Cited by web research for: Food Agriculture

Intel Summary

2

Techniques

40

Tools

0

Campaigns

41

IOCs

0

Observed Data

1

Tactics

Tags

Ransomware

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.