Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
Vexy Ransomware Claims Quy Nhon University (Vietnam) (TL-2026-2598) is a high-severity ransomware operation, first published 2026-09-21. It is attributed to Vexy Ransomware with low confidence, affects Quy Nhon University Google Workspace email environment, maps to 10 MITRE ATT&CK techniques (T1078, T1090, T1213), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-2598
- Threat ID
- TL-2026-2598
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-09-21
- Last reviewed
- 2026-09-21
- Attribution
- Vexy Ransomware
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- education
- Target regions
- Southeast Asia, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Vexy Ransomware Claims Quy Nhon University (Vietnam)
Malware and tooling: Vexy Ransomware
Vexy Ransomware, a data-extortion group first tracked in early September 2026, added Quy Nhon University (QNU), a public multidisciplinary university in Binh Dinh Province, Vietnam, to its Tor leak site on 2026-09-19, claiming 50GB of exfiltrated data and threatening to publish the "full dump" absent negotiation. The claim is publicly unverified by QNU, a regulator, or any independent security firm, and coincides with separately-sourced dark-web/attack-surface telemetry showing large-scale pre-existing credential exposure tied to the university.
How Vexy Ransomware Claims Quy Nhon University (Vietnam) works
On 2026-09-19 at 07:54 UTC, the leak-site tracker ransomware.live listed Quy Nhon University (qnu.edu.vn), a public, multidisciplinary Vietnamese university established in 1977 with a long-standing tradition in teacher education, as a victim of "Vexy Ransomware," a group the tracker explicitly labels a new/unverified actor whose claims "should be treated with caution until independently verified." The listing records an estimated attack date of 2026-09-18 and a claim of 50GB of exfiltrated data, alongside a direct ultimatum attributed to the group: "The full dump will be made available unless representatives from Quy Nhon University negotiate with us promptly." No regulator, breach-notification clearinghouse, or independent cybersecurity firm has confirmed that data left QNU's systems, and QNU itself has not publicly acknowledged contact with the group, data theft, or a security incident. Coverage from malware.news, DeXpose, GalaxyWarden, and HookPhish uniformly frames the listing as an extortion-stage assertion rather than confirmed proof of compromise; GalaxyWarden explicitly cautions that groups often "list organisations quickly to create urgency even when the claim is recycled from an older compromise, exaggerated, or entirely fabricated."
Vexy Ransomware itself is an emerging, financially motivated data-extortion operation. Ransomware.live's group profile dates its first tracked attack to 2026-09-02 (victim Engefitas, a Brazilian manufacturer) with discovery on 2026-09-03, and WatchGuard's independent tracker corroborates this earliest-activity window. WatchGuard classifies Vexy as a "data broker" style ransomware operation employing both direct extortion (data theft without confirmed encryption) and double extortion (data theft plus an encryption/leak threat). The group runs a Tor-hosted leak/negotiation site at vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd[.]onion (Apache 2.4.68 on Debian, ~91.9% 30-day uptime as of 2026-09-21, last crawled 2026-09-21 05:36:53 UTC), lists two Bitcoin wallet addresses for ransom payment, and provides a Tox-protocol messenger identifier for direct victim negotiation — consistent with the peer-to-peer encrypted chat channels favored by other extortion crews to avoid centralized takedown.
As of 2026-09-19 to 2026-09-21, ransomware.live's group profile lists 15 confirmed Vexy victims across 10 countries, totaling 578.6GB of cumulative claimed exfiltration and an average attack-to-discovery delay of roughly one day: India (5 victims — the group's heaviest concentration, including i2k2 Networks, United Group, Sancity, Palsana Enviro/PEPL, and Annapurna Fashion), Brazil (2 — Engefitas and Logar Network Solutions), and one victim each in Vietnam (Quy Nhon University), Italy (STP Fashion Lab), Japan (Hashimoto Jimuki), the UK (Strad Solutions), Argentina (LIBRERIA SANTA FE), Mexico (Mega Velocity), the US (Sancity Soft Touch), and Ecuador (McDonald's Ecuador, a recognizable multinational franchise illustrating the group's largely indiscriminate targeting). By sector, Technology (4 victims), Retail & E-Commerce (3), and Manufacturing (3) lead, with Education (QNU) representing the group's first and only publicly reported higher-education victim to date — an outlier against its commodity commercial/industrial targeting pattern. Ransomware.live's operational metrics additionally report that 66.7% of Vexy's tracked victims are independently correlated with domain-level infostealer log exposure, indicating the group's targeting or claims lean heavily on credential material harvested by commodity infostealer malware rather than confirmed bespoke intrusion. No malware sample, encryption-extension identifier, ransom-note text, or confirmed initial-access technique for the group has surfaced in public reporting; every technical/incident-specific source consulted (malware.news, DeXpose, GalaxyWarden, HookPhish) explicitly states it contains no TTP, IOC, or attack-vector detail for the QNU incident specifically.
Separately from the Vexy claim itself, the ransomware.live listing surfaces third-party dark-web and attack-surface exposure data for QNU attributed to the monitoring vendor ParanoidLab: 32 compromised employees, 1,772 compromised users, 151 third-party employee credentials, 114 external attack-surface exposures, 12,269 exposed passwords (292 flagged critical), and 93 exposed cookies (12 flagged critical), alongside infrastructure fingerprinting showing QNU uses Google Workspace for email (primary MX records) and Microsoft Azure (portal-qnu.azurewebsites.net) for a web portal, with no traditional hosting provider identified in DNS records otherwise. This telemetry documents that credential and session material tied to QNU has circulated via infostealer logs/dark-web sources independent of any confirmed Vexy intrusion — consistent with the group's broader 66.7% infostealer-correlation pattern — and raises the plausibility of credential- or cookie-based access as a contributing risk factor, but does not by itself confirm Vexy's initial-access vector, which remains undisclosed in every source reviewed.
MITRE ATT&CK techniques used in TL-2026-2598
Initial Access
Command and Control
Collection
T1213 Data from Information Repositories
Credential Access
T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
Reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information
Impact
Affected products and versions in Vexy Ransomware Claims Quy Nhon University (Vietnam)
- Quy Nhon University — Google Workspace email environment
- Quy Nhon University — Azure-hosted web portal (portal-qnu.azurewebsites.net)
Remediation for Vexy Ransomware Claims Quy Nhon University (Vietnam)
Immediate actions
- Treat the claim as unverified but actionable: initiate a compromise assessment of QNU's Google Workspace tenant and the Azure-hosted portal-qnu.azurewebsites.net portal
- Force credential resets across staff, student, and third-party accounts given the scale of independently-reported password/cookie exposure (12,269 passwords, 93 cookies) tied to the domain
- Enable/verify multi-factor authentication on all Google Workspace and Azure-fronted accounts, and invalidate active web sessions given the 93 exposed session cookies
- Engage dark-web monitoring to watch for any data actually posted to Vexy's Tor leak site before/after the negotiation deadline
Longer-term hardening
- Stand up continuous dark-web and infostealer-log monitoring for institutional credentials, given the pre-existing large-scale exposure identified independent of this claim and the group's documented 66.7% infostealer-correlation rate across victims
- Deploy EDR with behavioral detection across endpoints and conduct regular phishing-awareness training to reduce infostealer infection risk
- Maintain offline, immutable backups and a tested incident-response/negotiation-refusal playbook for ransomware/extortion events
- Engage a qualified incident-response firm before any contact or negotiation with the group
Timeline of Vexy Ransomware Claims Quy Nhon University (Vietnam)
- Vexy Ransomware's earliest tracked attack date — victim Engefitas (Brazil, manufacturing sector) — per ransomware.live's group profile.
- Vexy Ransomware first publicly tracked/discovered as a new, unverified ransomware/data-extortion group; Engefitas (Brazil) and McDonald's Ecuador (Ecuador, hospitality) both listed as early victims.
- Vexy Ransomware lists three India/US victims the same day: Palsana Enviro (PEPL, manufacturing), Annapurna Fashion (retail/e-commerce), and Sancity Soft Touch (US, technology).
- Vexy Ransomware claims Mega Velocity (Mexico, transportation-sector software firm) as a victim.
- Vexy Ransomware lists United Group (India, 116GB claimed) and LIBRERIA SANTA FE (Argentina, retail) as victims; Sancity (India) is separately listed around the same period (discovered 2026-09-06).
- Vexy Ransomware lists Logar Network Solutions (Brazil, technology) as a victim.
- Vexy Ransomware lists i2k2 Networks (India, technology) as a victim.
- Vexy Ransomware lists Strad Solutions (UK, technology) as a victim, claiming 46.52GB of exfiltrated data.
- Vexy Ransomware lists Hashimoto Jimuki (Japan, manufacturing) as a victim — the group's most recent listing prior to the Quy Nhon University claim, showing a near-continuous weekly cadence.
- Vexy Ransomware lists STP Fashion Lab (Italy, retail/e-commerce) as a victim, claiming 79.94GB of exfiltrated data.
- Estimated attack/compromise date for Quy Nhon University per the ransomware.live listing.
- malware.news, DeXpose, GalaxyWarden, and HookPhish publish alerts on the QNU listing, each explicitly noting the claim is unverified and QNU has not confirmed contact, theft, or breach; GalaxyWarden cautions the rapid listing timeline is consistent with pressure tactics rather than a verified, investigated compromise.
- Vexy issues a public ultimatum: "The full dump will be made available unless representatives from Quy Nhon University negotiate with us promptly."
- Vexy Ransomware publicly lists Quy Nhon University (qnu.edu.vn) on its Tor leak site at 07:54 UTC, claiming 50GB of exfiltrated institutional data — the group's first and only reported higher-education victim to date.
- Vexy's Tor leak site (Apache 2.4.68/Debian) confirmed online with ~91.9% 30-day uptime, last crawled 05:36:53 UTC; group profile shows 15 confirmed victims across 10 countries, 578.6GB of cumulative claimed exfiltration, and a 66.7% infostealer-correlation rate across tracked victims.
Sources cited for Vexy Ransomware Claims Quy Nhon University (Vietnam)
- Ransomware.live victim listing: Quy Nhon University — Vexy Ransomware
- Ransomware.live group profile: Vexy Ransomware
- Vexy Ransomware Tracker Profile — WatchGuard Technologies
- Vexy Ransomware Targets Quy Nhon University in Vietnam
- Quy Nhon University Listed by Vexy Ransomware Ransomware Group
- Quy Nhon University Listed by Vexy Ransomware Group
- Vexy Ransomware Targets Quy Nhon University in Vietnam
- Ransomware Group Vexy Ransomware Hits: Mega Velocity
- Vexy Ransomware Ransomware Group Profile — SOCRadar
More in ransomware
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
- Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation
Detection coverage for TL-2026-2598
As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2598 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.