Vexy Ransomware (RaaS) claims Sancity (sancity.in) — Indian real estate/construction group; 130 MB data exfiltration alleged

Vexy Ransomware (RaaS) claims Sancity (sancity.in) (TL-2026-2352), also tracked as Vexy Ransomware, is a medium-severity ransomware operation, first published 2026-09-06. It is attributed to Vexy Ransomware with low confidence, affects Sancity Realty India Limited Sancity corporate group web presence and, maps to 9 MITRE ATT&CK techniques (T1021.002, T1048, T1070.004), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-2352

Threat ID
TL-2026-2352
Also known as
Vexy Ransomware, Vexy RaaS, vexys RaaS
Severity
MEDIUM
Status
ACTIVE
Category
RANSOMWARE
First published
2026-09-06
Last reviewed
2026-09-06
Attribution
Vexy Ransomware
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
real estate, construction, it services, real-estate marketing sales
Target regions
india, South Asia
Detection rules
9
Indicators of compromise
19

Malware and tooling in Vexy Ransomware (RaaS) claims Sancity (sancity.in)

Malware and tooling: Dataleak, ESXi Locker, Linux Locker, Vexy Ransomware, Windows Locker, Tor - S0183

On 2026-09-06, ransomware tracker ransomware.live flagged a leak-site claim by Vexy Ransomware — an emerging Rust-based Ransomware-as-a-Service (RaaS) operation first seen in early September 2026 — against Sancity (sancity.in), an Indian real estate/construction group headquartered in Surat, Gujarat. The group alleges the exfiltration of 130 MB of data and threatens publication on its Tor leak site unless contacted. The claim is unverified, the leak is pending, and the group's onion site is currently down.

How Vexy Ransomware (RaaS) claims Sancity (sancity.in) works

Sancity (sancity.in) is the umbrella brand for a group of active, unlisted public companies incorporated in 2012 in Surat, Gujarat, India. Its principal entity, Sancity Realty India Limited (CIN U45201GJ2012PLC068457, RoC-Ahmedabad), operates in real estate/construction and real-estate marketing and sales, with the group also spanning software (Sancity Soft Touch, softtouch4u.com), travel, media, education, and infrastructure. ransomware.live discovered the Vexy claim against the Sancity sancity.in listing on 2026-09-06 at 15:00 UTC and flags the claim as unverified: the group alludes to 130 MB of exfiltrated data and a pending dark-web leak, with no extortion amount disclosed. Breach House independently tracked a related Vexy listing for Sancity Soft Touch (softtouch4u.com, the group's IT-services arm) dated 2026-09-04, with ~100 MB cited and leak status pending. The victim has not publicly confirmed the incident as of this writing.

Vexy Ransomware is an emerging Ransomware-as-a-Service (RaaS) operation that surfaced in early September 2026 and scaled rapidly, posting at least 7-14 victim listings across India, Brazil, Ecuador, Mexico, and the United States within roughly four days (first estimated attack 2026-09-02; first victims published 2026-09-03; latest observed activity 2026-09-06). The operator, using the handle 'vexys', runs the program on a private invite-only basis through a Tor onion control panel, with RaaS rules published from the ReHub cybercrime forum (effective 2026-09-02): a one-time $200 USD invite fee paid in Bitcoin, an automated wallet/payment pipeline, and three lockers — a Windows Locker, a Linux Locker, and an ESXi Locker — all built in Rust. The advertised tooling uses AES-256 symmetric encryption with RSA key wrapping, targets local disks and network-accessible shares (SMB/NFS and VMware datastores), supports selective file/folder/extension targeting, service/process termination, free-space wiping, event-log and trace removal, self-deletion after execution, persistence control, and printer-based notification delivery. The group operates a single Tor data leak site (vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd.onion, Apache 2.4.68 on Debian, blog-style), which ransomware-live and Breach House report as down as of 2026-09-06 after 100% uptime in its observed window. Contact channels include a qTox ID.

Vexy is classified by WatchGuard as a 'Data Broker' type using both direct and double extortion. Ransomware.live reports a 42.9% infostealer prevalence among Vexy-attributed victim domains, suggesting credential/stealer-derived initial access is part of the playbook. The threat's targeting skews heavily toward India (3-4 of the group's victims, including Palsana Enviro and Annapurna Fashion) and small-to-medium enterprises across services, retail/e-commerce, manufacturing, transportation, and hospitality (including a high-profile claim against the McDonald's Ecuador franchise operated by Arcos Dorados). Because the Sancity claim is unverified, no malware sample has been publicly analyzed to confirm the advertised encryption or persistence capabilities, and no public ransom note text or wallet address is available; the claim should be treated with caution until independently confirmed.

MITRE ATT&CK techniques used in TL-2026-2352

Lateral Movement

T1021.002 SMB/Windows Admin Shares

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Defense Evasion

T1070.004 File Deletion

Initial Access

T1078 Valid Accounts

Impact

T1489 Service Stop; T1490 Inhibit System Recovery

Persistence

T1547 Boot or Logon Autostart Execution

Resource Development

T1588.002 Tool

defense-impairment

T1685.005 Clear Windows Event Logs

Affected products and versions in Vexy Ransomware (RaaS) claims Sancity (sancity.in)

  • Sancity Realty India Limited — Sancity corporate group web presence and internal IT (sancity.in)
    Vulnerable versions: unknown
  • Sancity Group — Sancity Soft Touch IT-services arm (softtouch4u.com)
    Vulnerable versions: unknown

Remediation for Vexy Ransomware (RaaS) claims Sancity (sancity.in)

Immediate actions

  • Treat the claim as credible pending verification and begin incident-response triage
  • Preserve forensic evidence and monitor for publication of allegedly stolen data on the Vexy Tor leak site
  • Engage incident response professionals BEFORE initiating any communication with the threat actor
  • Run continuous dark-web monitoring for corporate accounts, the Sancity.sanity.in domain, and leaked data
  • Check for infostealer-derived credential exposure on sancity.in / softtouch4u.com domains and reset affected accounts

Workarounds

  • Restrict external access to RDP/VPN/remote-management interfaces
  • Block traffic to the known Vexy onion domain and monitor for associated infrastructure
  • Enhance logging on privileged account usage, share access, and authentication anomalies

Longer-term hardening

  • Maintain offline, immutable backups and periodically test restoration
  • Enforce phishing-resistant multi-factor authentication across all accounts and privileged elevation paths
  • Segment networks and restrict SMB/NFS share access to least privilege to blunt lateral spread
  • Deploy EDR with behavioral detection for ransomware TTPs: mass file encryption, service/process termination, event-log clearing
  • Institute dark-web and brand monitoring plus threat-intelligence integration for emerging RaaS campaigns

Timeline of Vexy Ransomware (RaaS) claims Sancity (sancity.in)

  • Sancity Realty India Limited incorporated (CIN U45201GJ2012PLC068457, RoC-Ahmedabad); real estate/construction group headquartered in Surat, Gujarat, India.
  • Vexy RaaS rules effective, published from the ReHub cybercrime forum: $200 USD Bitcoin invite code, Windows/Linux/ESXi Rust lockers, AES-256+RSA encryption; first estimated attack (Engefitas, Brazil) dated this day.
  • Vexy data leak site begins publishing victims; Engefitas (Brazil) and McDonald's Ecuador listed; group discovered and tracked by threat-intelligence platforms (Breach House, WatchGuard, RansomLook, Mallory, ThreatMon).
  • Vexy lists Sancity Soft Touch (softtouch4u.com), the IT-services arm of the Sancity group, alleging ~100 MB exfiltration with leak status pending; group also lists Annapurna Fashion and Palsana Enviro (PEPL), both Indian companies.
  • Mega Velocity (Mexico) listed by the group; press coverage of the Sancity Soft Touch claim published (DeXpose via National Cyber Security Consulting; UnderCode News).
  • Vexy Tor data leak site (vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd.onion) reported down after 100% observed uptime; leak for Sancity remains pending; claim unconfirmed by the victim.
  • ransomware.live discovers the Vexy claim against Sancity (sancity.in) at 15:00 UTC; 130 MB data exfiltration alleged; extortion demand not listed; claim flagged as unverified.

Sources cited for Vexy Ransomware (RaaS) claims Sancity (sancity.in)

More in ransomware

Detection coverage for TL-2026-2352

As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2352 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats