SEXi
- First seen
- 2022-07-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:15:37
Targeted industries: technology-and-telecommunications professional-services government-and-public-sector healthcare-and-pharmaceutical
Context
SEXi is a ransomware group that targets VMware ESXi servers, encrypting data and demanding ransom payments. They have been observed encrypting virtual machines and backups, causing significant disruptions to services. The group's name is a play on the word "ESXi," indicating a deliberate focus on these systems. SEXi has been linked to other ransomware variants based on the Babuk source code.
Reports & references
- cybersecurity-insiders.com — Proven Data Restores Powerhosts Vmware Backups After Sexi Ransomware Attack (report)
- heimdalsecurity.com — Powerhosts Esxi Servers Encrypted With New Sexi Ransomware (report)
- darkreading.com — Sexi Ransomware Desires Vmware Hypervisors (report)