Threat reportRansomwareTL-2026-3271

Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)

mediumACTIVE

Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated) (TL-2026-3271) is a medium-severity ransomware operation, first published 2026-10-10. It is attributed to Vexy Ransomware with low confidence, affects KOOKABARRA JUICE Corporate IT environment (kookabarra.com), maps to 3 MITRE ATT&CK techniques (T1078, T1566, T1657), and is covered by 9 detection rules and 8 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
3MITRE ATT&CK
Actors
1Vexy Ransomware
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-3271

Threat ID
TL-2026-3271
Severity
MEDIUM
Status
ACTIVE
Category
RANSOMWARE
First published
Last reviewed
Attribution
Vexy Ransomware
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
agriculture-food-production, retail-ecommerce, manufacturing, technology
Target regions
australia, india, brazil, North America, timor leste
Detection rules
9
Indicators of compromise
8

Malware and tooling in Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)

Malware and tooling: Vexy Ransomware

How Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated) works

Ransomware.live lists KOOKABARRA JUICE (kookabarra.com), a fresh-pressed fruit juice manufacturer, as a victim of the Vexy Ransomware extortion group on 2026-10-06, with 37 GB reported exfiltrated. The claim comes from a leak-site tracker; no technical attack details, CVEs or attacker tooling are published.

On 2026-10-06 (20:55 UTC) Ransomware.live recorded KOOKABARRA JUICE (kookabarra.com) as a victim of the Vexy Ransomware group, with an estimated attack date of the same day and 37 GB of data reported exfiltrated. The company is described as a manufacturer of fresh-pressed fruit juices, detox juices, smoothies, nectars and other fresh fruit products. The tracker classifies the sector as Agriculture and Food Production (also Retail & E-Commerce) and lists the country as Australia, although the company description calls it French; the two are not reconciled in the source.

The victim page includes HudsonRock infostealer telemetry: 1 compromised user, 0 compromised employees, 0 third-party employee credentials, 11 exposed passwords (none critical), 0 exposed cookies and 1 external attack surface indicator. This is exposure context only; the source does not state that these credentials were used in the intrusion. The victim uses Microsoft 365 email, with MX records pointing to Outlook protection. The SPF-record IP addresses on the page belong to the victim's mail infrastructure and are not attacker IOCs, so they are excluded.

Vexy Ransomware is a data-extortion group operating a Tor leak site. Ransomware.live tracks 19 victims across 13 countries and 692.7 GB of reported exfiltrated data, with the first victim's estimated attack date on 2026-07-06, first listing discovered 2026-09-03 and last activity 2026-10-06. Top target countries are India (5), the United States (2), Brazil (2), Australia and Timor-Leste; the main sectors are Technology, Retail & E-Commerce and Manufacturing. About 73.7% of victims with domain associations show an infostealer connection. A published victim notice (i2k2 Networks, 2026-09-10) shows the group threatening to publish a full leak unless the victim opens negotiations through provided channels, which is the pattern of exfiltration followed by extortion. A SOCRadar write-up on Groupe Proxitel (2026-09-29) describes generic access vectors (phishing, exposed credentials, unpatched vulnerabilities), but this is not specific to the group's observed intrusions.

No CVE, CVSS score, initial access vector, encryption method, malware sample or tooling is documented for this victim. Severity MEDIUM is an analyst assessment. The Tox ID and onion leak-site address come from the Ransomware.live group profile.

MITRE ATT&CK techniques used in TL-2026-3271

Initial Access

T1078 Valid Accounts; T1566 Phishing

Impact

T1657 Financial Theft

Affected products and versions in Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)

  • KOOKABARRA JUICE — Corporate IT environment (kookabarra.com)

Remediation for Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)

Immediate actions

  • Reset credentials and revoke sessions for any account appearing in infostealer exposure reports, and enforce MFA on Microsoft 365
  • Review Microsoft 365 sign-in and audit logs for anomalous logins, mailbox rules and bulk downloads around 2026-10-06
  • Block and alert on the Vexy leak-site onion address and Tor egress from corporate networks where not required

Longer-term hardening

  • Monitor infostealer-exposure feeds (e.g. HudsonRock) for corporate domains and rotate exposed passwords
  • Maintain offline, tested backups and egress monitoring for large outbound transfers
  • Reduce external attack surface and patch internet-facing systems promptly

Timeline of Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)

  • Estimated attack date of the first Vexy Ransomware victim tracked by Ransomware.live
  • Ransomware.live discovers the first Vexy Ransomware leak-site victim listing
  • Vexy claims i2k2 Networks (India) and threatens a full leak unless the victim opens negotiations
  • Vexy lists Groupe Proxitel (Timor-Leste) on its leak site
  • Ransomware.live records KOOKABARRA JUICE as a Vexy Ransomware victim (20:55 UTC)
  • Estimated attack date for KOOKABARRA JUICE; 37 GB reported exfiltrated
  • Vexy onion leak site last visited by Ransomware.live; the group tracks 19 victims and 692.7 GB claimed

Sources cited for Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)

Detection coverage for TL-2026-3271

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3271 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats