Threat reportRansomwareTL-2026-3271
Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)
Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated) (TL-2026-3271) is a medium-severity ransomware operation, first published 2026-10-10. It is attributed to Vexy Ransomware with low confidence, affects KOOKABARRA JUICE Corporate IT environment (kookabarra.com), maps to 3 MITRE ATT&CK techniques (T1078, T1566, T1657), and is covered by 9 detection rules and 8 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 3MITRE ATT&CK
- Actors
- 1Vexy Ransomware
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-3271
- Threat ID
- TL-2026-3271
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- Vexy Ransomware
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- agriculture-food-production, retail-ecommerce, manufacturing, technology
- Target regions
- australia, india, brazil, North America, timor leste
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)
Malware and tooling: Vexy Ransomware
How Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated) works
Ransomware.live lists KOOKABARRA JUICE (kookabarra.com), a fresh-pressed fruit juice manufacturer, as a victim of the Vexy Ransomware extortion group on 2026-10-06, with 37 GB reported exfiltrated. The claim comes from a leak-site tracker; no technical attack details, CVEs or attacker tooling are published.
On 2026-10-06 (20:55 UTC) Ransomware.live recorded KOOKABARRA JUICE (kookabarra.com) as a victim of the Vexy Ransomware group, with an estimated attack date of the same day and 37 GB of data reported exfiltrated. The company is described as a manufacturer of fresh-pressed fruit juices, detox juices, smoothies, nectars and other fresh fruit products. The tracker classifies the sector as Agriculture and Food Production (also Retail & E-Commerce) and lists the country as Australia, although the company description calls it French; the two are not reconciled in the source.
The victim page includes HudsonRock infostealer telemetry: 1 compromised user, 0 compromised employees, 0 third-party employee credentials, 11 exposed passwords (none critical), 0 exposed cookies and 1 external attack surface indicator. This is exposure context only; the source does not state that these credentials were used in the intrusion. The victim uses Microsoft 365 email, with MX records pointing to Outlook protection. The SPF-record IP addresses on the page belong to the victim's mail infrastructure and are not attacker IOCs, so they are excluded.
Vexy Ransomware is a data-extortion group operating a Tor leak site. Ransomware.live tracks 19 victims across 13 countries and 692.7 GB of reported exfiltrated data, with the first victim's estimated attack date on 2026-07-06, first listing discovered 2026-09-03 and last activity 2026-10-06. Top target countries are India (5), the United States (2), Brazil (2), Australia and Timor-Leste; the main sectors are Technology, Retail & E-Commerce and Manufacturing. About 73.7% of victims with domain associations show an infostealer connection. A published victim notice (i2k2 Networks, 2026-09-10) shows the group threatening to publish a full leak unless the victim opens negotiations through provided channels, which is the pattern of exfiltration followed by extortion. A SOCRadar write-up on Groupe Proxitel (2026-09-29) describes generic access vectors (phishing, exposed credentials, unpatched vulnerabilities), but this is not specific to the group's observed intrusions.
No CVE, CVSS score, initial access vector, encryption method, malware sample or tooling is documented for this victim. Severity MEDIUM is an analyst assessment. The Tox ID and onion leak-site address come from the Ransomware.live group profile.
MITRE ATT&CK techniques used in TL-2026-3271
Initial Access
T1078 Valid Accounts; T1566 Phishing
Impact
Affected products and versions in Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)
- KOOKABARRA JUICE — Corporate IT environment (kookabarra.com)
Remediation for Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)
Immediate actions
- Reset credentials and revoke sessions for any account appearing in infostealer exposure reports, and enforce MFA on Microsoft 365
- Review Microsoft 365 sign-in and audit logs for anomalous logins, mailbox rules and bulk downloads around 2026-10-06
- Block and alert on the Vexy leak-site onion address and Tor egress from corporate networks where not required
Longer-term hardening
- Monitor infostealer-exposure feeds (e.g. HudsonRock) for corporate domains and rotate exposed passwords
- Maintain offline, tested backups and egress monitoring for large outbound transfers
- Reduce external attack surface and patch internet-facing systems promptly
Timeline of Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)
- Estimated attack date of the first Vexy Ransomware victim tracked by Ransomware.live
- Ransomware.live discovers the first Vexy Ransomware leak-site victim listing
- Vexy claims i2k2 Networks (India) and threatens a full leak unless the victim opens negotiations
- Vexy lists Groupe Proxitel (Timor-Leste) on its leak site
- Ransomware.live records KOOKABARRA JUICE as a Vexy Ransomware victim (20:55 UTC)
- Estimated attack date for KOOKABARRA JUICE; 37 GB reported exfiltrated
- Vexy onion leak site last visited by Ransomware.live; the group tracks 19 victims and 692.7 GB claimed
Sources cited for Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)
- Ransomware.live victim entry: KOOKABARRA JUICE (Vexy Ransomware)
- Ransomware.live group profile: Vexy Ransomware
- SOCRadar: Groupe Proxitel Data Breach (Vexy Ransomware)
- DEXPOSE: Vexy Ransomware Compromises i2k2 Networks
- DEXPOSE: Vexy Ransomware Targets Logar Network Solutions in Brazil
- DEXPOSE: Vexy Ransomware Strikes at Libreria Santa Fe
Detection coverage for TL-2026-3271
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3271 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.