# Vexy Ransomware claims KOOKABARRA JUICE (37 GB exfiltrated)

> Ransomware.live lists KOOKABARRA JUICE (kookabarra.com), a fresh-pressed fruit juice manufacturer, as a victim of the Vexy Ransomware extortion group on 2026-10-06, with 37 GB reported exfiltrated. The claim comes from a leak-site tracker; no technical attack details, CVEs or attacker tooling are published.

- **Published:** 2026-10-10T15:11:49Z
- **Last reviewed:** 2026-10-10T15:11:49Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3271
- **ID:** TL-2026-3271
- **Severity:** MEDIUM
- **Category:** RANSOMWARE
- **Status:** ACTIVE
- **Actor:** Vexy Ransomware
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-10-06 (20:55 UTC) Ransomware.live recorded KOOKABARRA JUICE (kookabarra.com) as a victim of the Vexy Ransomware group, with an estimated attack date of the same day and 37 GB of data reported exfiltrated. The company is described as a manufacturer of fresh-pressed fruit juices, detox juices, smoothies, nectars and other fresh fruit products. The tracker classifies the sector as Agriculture and Food Production (also Retail & E-Commerce) and lists the country as Australia, although the company description calls it French; the two are not reconciled in the source.

The victim page includes HudsonRock infostealer telemetry: 1 compromised user, 0 compromised employees, 0 third-party employee credentials, 11 exposed passwords (none critical), 0 exposed cookies and 1 external attack surface indicator. This is exposure context only; the source does not state that these credentials were used in the intrusion. The victim uses Microsoft 365 email, with MX records pointing to Outlook protection. The SPF-record IP addresses on the page belong to the victim's mail infrastructure and are not attacker IOCs, so they are excluded.

Vexy Ransomware is a data-extortion group operating a Tor leak site. Ransomware.live tracks 19 victims across 13 countries and 692.7 GB of reported exfiltrated data, with the first victim's estimated attack date on 2026-07-06, first listing discovered 2026-09-03 and last activity 2026-10-06. Top target countries are India (5), the United States (2), Brazil (2), Australia and Timor-Leste; the main sectors are Technology, Retail & E-Commerce and Manufacturing. About 73.7% of victims with domain associations show an infostealer connection. A published victim notice (i2k2 Networks, 2026-09-10) shows the group threatening to publish a full leak unless the victim opens negotiations through provided channels, which is the pattern of exfiltration followed by extortion. A SOCRadar write-up on Groupe Proxitel (2026-09-29) describes generic access vectors (phishing, exposed credentials, unpatched vulnerabilities), but this is not specific to the group's observed intrusions.

No CVE, CVSS score, initial access vector, encryption method, malware sample or tooling is documented for this victim. Severity MEDIUM is an analyst assessment. The Tox ID and onion leak-site address come from the Ransomware.live group profile.

## MITRE ATT&CK

- T1657 Financial Theft
- T1078 Valid Accounts
- T1566 Phishing

## Sources

- [Ransomware.live victim entry: KOOKABARRA JUICE (Vexy Ransomware)](https://www.ransomware.live/id/S09PS0FCQVJSQSBKVUlDRUBWZXh5IFJhbnNvbXdhcmU=)
- [Ransomware.live group profile: Vexy Ransomware](https://www.ransomware.live/group/vexy)
- [SOCRadar: Groupe Proxitel Data Breach (Vexy Ransomware)](https://socradar.io/blog/data-breach/groupe-proxitel-vexy-ransomware-2026/)
- [DEXPOSE: Vexy Ransomware Compromises i2k2 Networks](https://www.dexpose.io/vexy-ransomware-compromises-i2k2-networks/)
- [DEXPOSE: Vexy Ransomware Targets Logar Network Solutions in Brazil](https://www.dexpose.io/vexy-ransomware-targets-logar-network-solutions-in-brazil/)
- [DEXPOSE: Vexy Ransomware Strikes at Libreria Santa Fe](https://www.dexpose.io/vexy-ransomware-strikes-at-libreria-santa-fe/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3271
