A bookshop chain in Buenos Aires, the operator of McDonald's restaurants in Ecuador, and an Indian company that runs data centre space for other firms have one thing in common this month. All three were posted to the leak site of a ransomware crew that did not exist two weeks ago.
The crew calls itself Vexy. Its first victim listing went up on 3 September. By 12 September it had named 13, and almost none of them are where a new ransomware operation usually starts.
Ten days, thirteen names
IntelFusions tracks extortion listings as they appear on leak sites, the pages where crews name organizations they say they have breached to pressure them into paying. Vexy's 13 posts cover 12 distinct organizations, with the Ecuadorian McDonald's franchise business listed twice, on 3 and 6 September. Its Tor site was still online on 13 September.
These are claims, not confirmed breaches: assertions by criminals with an obvious motive to exaggerate, and none of the organizations named has confirmed one. We could not find a single published vendor analysis of Vexy, so nobody outside the crew has yet described what its malware does.
The map points away from North America
About seven in ten of the leak-site listings IntelFusions has recorded over the past quarter fall in North America or Europe. Vexy has gone almost everywhere else. Eleven of its 13 listings are companies in India or Latin America: five in India, two in Brazil, two naming the same Ecuadorian operator, one in Argentina and one in Mexico. The other two are a hosting firm tagged to the United Kingdom, which markets itself mainly to Indian buyers, and an IT services company tagged to the United States.
India has been moving this way for months. IntelFusions reported in August that leak-site claims against Indian firms had tripled in a month, and India carries a Critical targeting level in our country profile. The Indian victims are ordinary industrial firms, among them an effluent treatment operator and a raised access flooring maker trading as Unitile.
Three victims host other companies' systems
The detail worth pausing on is what several of these businesses do. We checked their own websites rather than relying on leak-site blurbs. i2k2 Networks sells dedicated servers, cloud hosting and data centre services in India. Logar Network Solutions runs outsourced IT management, security and infrastructure for Brazilian companies across six states. Strad Solutions sells cloud VPS and dedicated servers to the Indian market.
All three are businesses that other businesses depend on. When a hosting company or a managed IT provider is compromised, the blast radius is not one organization, it is every customer whose systems that provider can reach. That is why a cluster of unfamiliar names is worth watching.
Judge your provider, not just your perimeter
There is no patch here. This is a supply chain question, and a supplier's security is your security. Ask your hosting company and your managed IT provider whether their administrative access into your environment is separated and monitored, whether their remote management tooling requires phishing-resistant multi-factor authentication, and how fast they would tell you if they were breached. Keep backups somewhere the provider's credentials cannot reach.
Vexy has published no file hashes, no ransom note samples and no infrastructure defenders could hunt for, and nor has anyone else. Its only signal is the list of names on its own leak site, which is a poor early warning: by the time a company appears there, the intrusion is finished. A crew this new could change shape within a month. What it has shown in ten days is a preference for markets where security spending is thinner, and for companies holding the keys to other people's networks. Listings are tracked at ransomware.live; our record sits on the Vexy actor profile.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.