Also known as: SOCOTRA, FORMOSA, CVE-2025-55182, Project Spy, Cridex, U2DiskWatch, similar to Sliver, Cobalt Strike, consists of multiple components, control module, NoFive, Plat1, keygroup777, TA558, CVE-2025-53770, CVE-2025-53771, CVE-2025-32433, OTP's SSH implementation, CVE-2025-22224, CVE-2025-22225, LockBit 3.0, CVE-2025-23006, CVE-2024-55956, 419, advanced fee scam, to the economic, BokBot
SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines and backups, causing significant disruptions to services. The group's name is a play on the word "ESXi," indicating a deliberate focus on these systems. SEXi has been linked to other ransomware variants based on the Babuk source code.
Targeted Sectors
Targeted Countries / Regions
No AI analysis yet.
No campaigns linked yet.
No observed data linked yet.
2
Techniques
40
Tools
0
Campaigns
41
IOCs
0
Observed Data
1
Tactics