Ransomware Group intelligence
Vexy Ransomware
ActiveTrack Vexy Ransomware with 26 published victims and 1 known leak locations in a single intelligence view.
Overview
Vexy Ransomware is tracked by Dark Eye as a ransomware group with 26 published victims.
India is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Leak Status Distribution
- Leaked 0 0.0%
- Pending 12 92.3%
- Deleted 1 7.7%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 2h ago | vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd.onion |
Top Activity Sectors (7)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Vexy Ransomware, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: Vexy Ransomware executes malicious commands through PowerShell scripts to deploy payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: Vexy Ransomware modifies Windows Registry Run keys and startup folders to ensure persistence across reboots.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: Vexy Ransomware disables antivirus tools by modifying Windows Defender and security service configurations to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: Vexy Ransomware deletes Volume Shadow Copies and backup directories via vssadmin and command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1083 File and Directory Discovery Discovery
What they do: Vexy Ransomware uses file and directory discovery via PowerShell to enumerate critical user and system folders before encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1560.001 Archive via Utility Collection
What they do: Vexy Ransomware archives victim data using built-in utility commands before exfiltration to maintain leverage.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: Vexy Ransomware encrypts victim files using AES-256 symmetric encryption, targeting documents, images, and business data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: Vexy Ransomware inhibits system recovery by terminating critical Windows services like backup and monitoring utilities.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (26)
Search, filter and paginate the victim timeline for Vexy Ransomware. Showing 1–26 of 26.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Strad Solutions id32996 View details | United Kingdom | IT | — | pending | |
|
StradSolutions.com operates within the information technology sector and serves as a business entity located in the United Kingdom. The company is documented within this threat-intelligence index under the listing type ransomware victim, associated with the Vexy Ransomware threat actor. This classification reflects the entity's inclusion in records concerning cyber incidents involving this specific ransomware campaign. The description remains neutral and factual, focusing on the established categorization without extrapolating beyond verified intelligence. StradSolutions.com was listed as a ransomware victim associated with Vexy Ransomware. |
||||||
| Ransomware | Strad Solutions id32996 View details | United Kingdom | IT | — | pending | |
|
Strad Solutions provides cloud hosting, dedicated servers, managed IT, cybersecurity, and disaster recovery services for businesses worldwide. |
||||||
| Ransomware | i2k2 Networks id32751 View details | India | IT | — | pending | |
|
i2k2.com operates within the IT sector and is based in India. The entity functions as a technology services provider, contributing to the digital infrastructure landscape. Within the threat-intelligence index, i2k2.com is formally cataloged as a ransomware victim linked to the Vexy Ransomware threat actor. This listing type identifies the entity's involvement in a cyber incident attributed to this specific threat group. The entry reflects the cybersecurity context surrounding the organization without disclosing unverified incident details or confirming specific breach elements. |
||||||
| Ransomware | i2k2 Networks id32751 View details | India | IT | — | pending | |
|
i2k2 Networks Pvt. Ltd., established in 1999, is a leading Indian provider of cloud computing, web hosting, managed IT, data center, backup, disaster recovery, and DevOps solutions. With 25+ years of experience, 4,000+ customers, Tier III-compliant data centers, and 24/7 support, i2k2 delivers secure, scalable, and reliable IT solutions worldwide. |
||||||
| Ransomware | Logar Network Solutions id32716 View details | Brazil | Services | — | pending | |
|
logar.com.br operates within the Services sector and is based in Brazil, providing business and service-oriented offerings within its regional market. The entity is cataloged in the threat-intelligence index under the classification ransomware victim, specifically linked to the Vexy Ransomware threat actor. This listing documents the association between the organization and the identified ransomware campaign without disclosing unverified incident details such as data exfiltration scope, ransom demands, or confirmed breach specifics. The record serves to inform stakeholders of the cybersecurity exposure profile and contextualize the threat actor's targeting behavior within the Services sector in Brazil. It remains a factual reference point for monitoring ransomware incidents and associated threat actor activity. |
||||||
| Ransomware | Logar Network Solutions id32716 View details | Brazil | Services | — | pending | |
|
Logar Network Solutions is a Brazilian managed IT services provider (MSP) that delivers outsourced IT management, cybersecurity, cloud infrastructure, backup and disaster recovery, software licensing, hardware lifecycle management, and custom software development. The company primarily serves medium-sized businesses across multiple industries, offering 24/7 IT monitoring and support. It has served more than 500 companies and operates across six Brazilian states. |
||||||
| Ransomware | United Group id32643 View details | India | Services | — | pending | |
|
united-group.in operates within the Services sector and is based in India, providing business-oriented services consistent with its domain identity. The entity has been documented within a threat-intelligence index under the listing type ransomware victim, specifically associated with the Vexy Ransomware threat actor. This classification reflects its inclusion in cybersecurity records concerning ransomware incidents affecting organizations in its geographic and sectoral context. The description adheres to neutral, authoritative reporting standards without disclosing unverified incident details such as data exfiltration specifics, financial impact, or confirmed breach evidence. united-group.in was listed as a ransomware victim associated with Vexy Ransomware. |
||||||
| Ransomware | United Group id32643 View details | India | Services | — | pending | |
|
United Group is a diversified Indian business group delivering innovative products and services across multiple industries. Founded in 2003, the company began as a food and beverage consultancy and has since expanded into food ingredients, nutraceuticals, industrial machinery, infrastructure, fashion, digital branding, packaging, and automotive accessories. With a strong focus on quality, innovation, and customer satisfaction, United Group operates through a network of specialized businesses, serving clients across India and international markets. Backed by certified manufacturing facilities and experienced professionals, the group is committed to providing reliable, sustainable, and value-driven solutions that support business growth and long-term success. |
||||||
| Ransomware | LIBRERIA SANTA FE A P S SRL id32628 View details | Argentina | Telecommunications | — | deleted | |
|
lsf.com.ar operates within the telecommunications sector and is situated in Argentina (country code AR). The entity represents a business organization whose infrastructure was impacted by a ransomware incident linked to the Vexy Ransomware threat actor. This listing type identifies lsf.com.ar specifically as a ransomware victim within the threat-intelligence index, reflecting its association with this cyber threat. The description focuses on the entity's verified sector, geographic origin, and the confirmed threat actor connection without disclosing unverified incident details such as data exfiltration specifics, ransom demands, or internal breach confirmations. This catalog entry serves to inform security analysts and defenders about a real-world telecommunications organization affected by Vexy Ransomware activity. |
||||||
| Ransomware | LIBRERIA SANTA FE A P S SRL id32628 View details | Argentina | Telecommunications | — | deleted | |
|
LSF (Librería Santa Fe) is a bookstore based in Buenos Aires, Argentina, with multiple branches across the city (CABA). It offers a wide selection of both national and imported books across various genres and authors. The store provides an easy online shopping experience where customers can browse and purchase titles with just a few clicks. It also maintains an active social media presence on Instagram (@libreriasantafe) to share news, promotions, and updates. Visitors are welcome to visit their physical locations in person. |
||||||
| Ransomware | Sancity id32618 View details | India | Finance / Legal / Insurance | — | pending | |
|
sancity.in operates within the finance, legal, and insurance sectors and is situated in India. Its domain serves as a reference point within a threat-intelligence index catalog documenting cybersecurity incidents affecting organizations across critical industries. This listing type identifies sancity.in as a ransomware victim linked to the Vexy Ransomware threat actor. The entry provides neutral context for researchers, defenders, and industry stakeholders monitoring evolving ransomware activity in finance and legal service domains. No incident specifics, breach confirmations, or unverified claims are included in this description. |
||||||
| Ransomware | Sancity id32618 View details | India | Finance / Legal / Insurance | — | pending | |
|
An active, unlisted public company incorporated in 2012, operating in real estate/construction and real-estate marketing & sales |
||||||
| Ransomware | McDonalds Ecuador id32612 View details | Ecuador | Hospitality / Food & Beverage / Tourism | — | pending | |
|
mcdonalds.com.ec represents a domain associated with the McDonald's brand operating within the Hospitality, Food & Beverage, and Tourism sectors, with operational presence linked to the EC region. This entity functions as a web presence supporting restaurant services, customer engagement, and industry-specific digital operations across the food and tourism landscape. Within threat-intelligence indexing frameworks, mcdonalds.com.ec is cataloged as a ransomware victim, specifically associated with the Vexy Ransomware threat actor. This classification reflects cybersecurity monitoring observations linking the domain to malicious activity without disclosing unverified technical details or incident specifics. The listing underscores ongoing vigilance across hospitality infrastructure against evolving ransomware threats in regional markets. |
||||||
| Ransomware | McDonalds Ecuador id32612 View details | Ecuador | Hospitality / Food & Beverage / Tourism | — | pending | |
|
McDonalds Ecuador is the local franchise operation of the global McDonalds brand. The company operates fast-food restaurants across Ecuador, offering products such as burgers, fries, beverages, breakfast items, and childrens meals. It operates under the McDonalds franchise model through Arcos Dorados, the largest McDonalds franchise operator in Latin America and the Caribbean. |
||||||
| Ransomware | Mega Velocity id32605 View details | Mexico | Transportation / Travel / Logistics | — | pending | |
|
megavelocity.net operates within the Transportation, Travel, and Logistics sector and is identified as a ransomware victim within a threat-intelligence index. The entity represents infrastructure relevant to mobility and supply chain continuity, making it significant for cyber-risk analysis in sectors where operational disruption carries high economic and safety implications. This listing reflects an association with Vexy Ransomware, a threat actor documented for targeting organizations through ransomware-based attacks. No specific incident details, such as data exfiltration scope, ransom demands, or confirmed breach evidence, are included to maintain factual neutrality and avoid speculative claims. The entry serves catalog and intelligence purposes for monitoring threat actor activity and sector exposure. |
||||||
| Ransomware | Mega Velocity id32605 View details | Mexico | Transportation / Travel / Logistics | — | pending | |
|
New Delhi–based private technology company incorporated in 2013. Its registered business classification is software publishing, consultancy and supply, including software development, maintenance and web-page design. Its network records also identify MEGA VELOCITY PVT LTD as an Internet/hosting network operator. |
||||||
| Ransomware | Palsana Enviro (PEPL) id32582 View details | India | Services | — | pending | |
|
palsanaenviro.com operates within the Services sector and is situated in India. The entity is cataloged within a threat-intelligence index under the listing type ransomware victim, explicitly linked to the Vexy Ransomware threat actor. This classification reflects its documented association with this specific cyber threat campaign without disclosing unverified incident details. The entry provides context for security teams monitoring ransomware activity across service-oriented organizations in the affected region. It neutrally records the relationship between palsanaenviro.com and Vexy Ransomware for analytical and defensive reference purposes. |
||||||
| Ransomware | Palsana Enviro (PEPL) id32582 View details | India | Services | — | pending | |
|
Environmental services company operating a Common Effluent Treatment Plant (CETP) for textile-processing industries. PEPL collects, treats and disposes of industrial wastewater and also recycles treated water for member industries. Its current stated treatment capacity is 150 MLD, with 50 MLD recycling capacity. |
||||||
| Ransomware | Annapurna Fashion id32583 View details | India | Retail / E-commerce | — | pending | |
|
annapurnafashion.com operates within the Indian retail and e-commerce sector, providing online fashion-related products and commerce services. As a ransomware victim linked to Vexy Ransomware, this entity appears in threat-intelligence indexes documenting cyber incidents affecting digital commerce infrastructure. The listing type identifies the relationship between the organization and the Vexy Ransomware threat actor, contextualizing security exposure within retail technology environments. No specific incident details such as data stolen, ransom demands, or breach confirmation are provided here, maintaining factual neutrality. This entry serves catalog and analytical purposes for monitoring cyber threats impacting e-commerce and retail domains globally. |
||||||
| Ransomware | Annapurna Fashion id32583 View details | India | Retail / E-commerce | — | pending | |
|
Manufacturer, supplier and exporter/distributor of fabrics and apparel-related products, including cotton fabrics, shirting, suiting, jacquard, sherwani fabrics, uniforms, ladies' tops and readymade garments |
||||||
| Ransomware | Sancity Soft Touch id32584 View details | United States | Retail / E-commerce | — | pending | |
|
Softtouch4u.com operates within the United States retail and e-commerce sector, providing digital commerce and customer engagement services typical of modern retail platforms. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with the associated threat actor identified as Vexy Ransomware. This classification reflects the cybersecurity context in which the organization was documented, linking its sector profile to a recognized ransomware campaign without disclosing unverified incident details. The entry serves to inform threat researchers and security professionals about potential exposure pathways within retail and e-commerce environments targeted by Vexy Ransomware. It was listed as a ransomware victim associated with Vexy Ransomware. |
||||||
| Ransomware | Sancity Soft Touch id32584 View details | United States | Retail / E-commerce | — | pending | |
|
IT services company providing web design & development, software/application development, payment gateway services, digital marketing, mobile applications, software testing and cloud-related services. |
||||||
| Ransomware | McDonald's Ecuador id32450 View details | Ecuador | Hospitality / Food & Beverage / Tourism | — | pending | |
|
mcdonalds.com.ec represents a domain associated with the McDonald's brand operating within the Hospitality, Food & Beverage, and Tourism sectors, primarily linked to the Economic Community of Africa (EC) region. This entity functions as a digital presence serving food service operations and customer engagement across its geographic market. Within threat-intelligence indexing frameworks, mcdonalds.com.ec is cataloged specifically as a ransomware victim, with the associated threat actor identified as Vexy Ransomware. The listing type reflects observed security event correlation rather than confirmed breach details, maintaining neutrality regarding unverified incident specifics. This entry documents the cybersecurity risk profile of an organization in the food and hospitality industry facing ransomware threats from the Vexy Ransomware group. |
||||||
| Ransomware | McDonald's Ecuador id32450 View details | Ecuador | Hospitality / Food & Beverage / Tourism | — | pending | |
|
McDonald's Ecuador is the local franchise operation of the global McDonald's brand. The company operates fast-food restaurants across Ecuador, offering products such as burgers, fries, beverages, breakfast items, and children's meals. It operates under the McDonald's franchise model through Arcos Dorados, the largest McDonald's franchise operator in Latin America and the Caribbean. |
||||||
| Ransomware | Engefitas id32444 View details | Brazil | Services | — | pending | |
|
engefitas.com.br operates within the Services sector and is headquartered in Brazil. The entity represents a business organization whose infrastructure or digital assets were identified within the threat-intelligence index as a ransomware victim linked to the Vexy Ransomware threat actor. This listing type indicates that the organization was affected by this specific malware campaign, contributing contextual data for analysts tracking cyber incidents across service-oriented sectors in Brazil. The description avoids speculative claims regarding breach details, data exfiltration, or financial impact, focusing solely on the verified association between the entity and the threat actor as documented in the index. Such catalog entries support threat-resilience efforts by mapping victim profiles to active ransomware campaigns. |
||||||
| Ransomware | Engefitas id32444 View details | Brazil | Services | — | pending | |
|
Engefitas is a Brazilian company that produces various adhesive tapes and adhesives for industries like packaging, automotive, construction, electronic, and manufacturing sectors. |
||||||