# Vexy Ransomware

> As of 2026-09-27, Vexy Ransomware is a threat actor tracked by Threadlinqs Intelligence across 4 threats spanning ransomware. ATT&CK coverage spans 29 techniques across 13 tactics in 4 of 4 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1048 (Exfiltration Over Alternative Protocol), T1090 (Proxy).

- **Tracked threats:** 4
- **Categories:** RANSOMWARE
- **As of:** 2026-09-27

## ATT&CK techniques observed

29 techniques observed across 4 of 4 tracked threats. Tactics: Impact (5), Resource Development (4), Credential Access (3), Initial Access (3), Command and Control (2), Defense Impairment (2).

- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 3 of 4 tracked threats
- [T1048](https://intel.threadlinqs.com/technique/T1048) Exfiltration Over Alternative Protocol — Exfiltration — observed in 2 of 4 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 2 of 4 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 2 of 4 tracked threats
- [T1489](https://intel.threadlinqs.com/technique/T1489) Service Stop — Impact — observed in 2 of 4 tracked threats
- [T1490](https://intel.threadlinqs.com/technique/T1490) Inhibit System Recovery — Impact — observed in 2 of 4 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 2 of 4 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 2 of 4 tracked threats
- [T1589](https://intel.threadlinqs.com/technique/T1589) Gather Victim Identity Information — Reconnaissance — observed in 2 of 4 tracked threats
- [T1591](https://intel.threadlinqs.com/technique/T1591) Gather Victim Org Information — Reconnaissance — observed in 2 of 4 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 2 of 4 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 4 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 1 of 4 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 4 tracked threats
- [T1070.004](https://intel.threadlinqs.com/technique/T1070.004) File Deletion — Stealth (formerly Defense Evasion) — observed in 1 of 4 tracked threats

## Tracked threats

- [Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)](https://intel.threadlinqs.com/threat/TL-2026-2713) — MEDIUM
- [Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated](https://intel.threadlinqs.com/threat/TL-2026-2598) — HIGH
- [Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion](https://intel.threadlinqs.com/threat/TL-2026-2363) — HIGH
- [Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data exfiltration alleged](https://intel.threadlinqs.com/threat/TL-2026-2352) — MEDIUM

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Vexy%20Ransomware
