Activity timeline
Vexy Ransomware appears in 4 tracked threats between and .
ATT&CK techniques observed
- T1078 Valid Accounts — Initial Accessobserved in 3 of 4 tracked threats
- T1048 Exfiltration Over Alternative Protocol — Exfiltrationobserved in 2 of 4 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 4 tracked threats
- T1213 Data from Information Repositories — Collectionobserved in 2 of 4 tracked threats
- T1489 Service Stop — Impactobserved in 2 of 4 tracked threats
- T1490 Inhibit System Recovery — Impactobserved in 2 of 4 tracked threats
- T1539 Steal Web Session Cookie — Credential Accessobserved in 2 of 4 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 4 tracked threats
- T1589 Gather Victim Identity Information — Reconnaissanceobserved in 2 of 4 tracked threats
- T1591 Gather Victim Org Information — Reconnaissanceobserved in 2 of 4 tracked threats
- T1657 Financial Theft — Impactobserved in 2 of 4 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 1 of 4 tracked threats
- T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 1 of 4 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 1 of 4 tracked threats
- T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 1 of 4 tracked threats
Tracked threats
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)MEDIUM
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB ExfiltratedHIGH
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortionHIGH
- Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data exfiltration allegedMEDIUM