Ransomware family
Vexy Ransomware Decryption & Data Recovery
- Active
- Medium
- No public decryptor
Vexy (written as New Vexy by some feeds) is an emerging extortion crew that surfaced in early September 2026. It runs its own Tor leak site and pressures victims with full-leak threats, mostly IT service and hosting providers and manufacturers in India and Latin America. Public technical data is minimal: no confirmed extension, note or decryptor.
- First seen
- 2026-09
- File extensions
- No public information
- Ransom notes
- No public information
- Affected platforms
- No public information
Public information on this family is limited. What follows is compiled from the small amount of verified material available, so please contact us for a sample assessment before you act on it.
Family profile
- File extensions
- No public information
- Ransom notes
- No public information
- Contact patterns
- Tor (.onion) leak site (onion name starts with vexy)
- Tox messenger ID
- No fixed mail domain observed publicly
- Aliases / versions
- New Vexy、Vexy Ransomware
- First seen
- 2026-09
- Status
- Active
- Operational status
- Newly emerged
- Threat level
- Medium
- Affected platforms
- No public information
- Tags
- Emerging
- Active
- Extortion-only
There is no free public decryptor for Vexy. The family is not listed on No More Ransom, and no vendor or law-enforcement agency has released keys or a decryption tool for it.
More fundamentally, as of 2026-09-11 no vendor has published a sample analysis of a Vexy encryptor, so whether its crypto implementation has an exploitable flaw is unknown. If your files are genuinely encrypted, identify the family and build from real encrypted files and the ransom note first, then assess recovery paths - do not run an unverified "Vexy decryptor" against original disks. Tools that appear right after a new brand emerges are frequently follow-on scams or damage file structures.
Latest activity
About ten days in, Vexy had listed 11 organisations, most of them Indian. RansomLook logs only about one-third uptime for its onion site over 30 days.
SourcesIndian hosting and cloud provider i2k2 Networks was listed on the Vexy leak site, underlining the crew's focus on small and mid-sized IT and hosting providers.
SourcesVexy's Tor leak site was first indexed by public trackers, with the earliest claimed victim (Brazilian manufacturer Engefitas) dated 2 September 2026.
Sources
Overview
Vexy first appeared on the dark web in early September 2026. ransomware.live and RansomLook began recording its leak site on 3 September, with the earliest claimed attack dated 2 September; by 11 September the trackers listed between 10 and 12 organisations, depending on how each counts. Victims cluster in India (IT services, hosting and cloud, manufacturing, retail), with the rest spread across Brazil, Argentina, Mexico and Ecuador. No public report places Vexy against mainland China organisations.
The caveat matters: public information on this family is very limited. As of 2026-09-11 no major vendor or CERT has published a sample analysis or IOC set for Vexy. Claims circulating in Chinese-language media about a Rust cross-platform encryptor and an affiliate entry fee appear only in secondary write-ups with no vendor analysis or sample behind them; we cannot verify them and do not repeat them as fact. What is confirmed: a dedicated Tor leak site (its onion name starts with vexy; reported uptime varies widely between trackers), Tox as the contact channel, and posts threatening full publication unless the victim makes contact - trackers generally describe the group as stealing data first and extorting second. This page will be updated as reporting matures.
How to identify it
Vexy has no publicly documented extension or ransom note filename, so extension matching cannot identify it. Attribution currently rests on the extortion side: the organisation appears on an .onion leak site whose name starts with vexy, in a post that typically carries a company profile, an attacker-claimed data volume and a sample pack; contact is directed to Tox rather than email; and the wording centres on full publication if the victim does not make contact, with no mention of decryption.
If files are also encrypted, preserve three to five encrypted samples and the original note. That material is first-hand intelligence and must be confirmed by reverse engineering and comparison - do not self-attribute from a "new family" headline, because misattribution leads straight to the wrong recovery plan.
Infection vectors
No public report documents Vexy's initial access or lateral movement. The list below is a triage priority derived from its victim profile (small and mid-sized IT service providers, hosting and cloud companies, manufacturers), not a confirmed kill chain:
- Internet-exposed remote access without MFA (VPN, RDP, jump hosts) and known vulnerabilities in edge appliances.
- Managed-service and supply-chain pivots - several victims are themselves IT or hosting providers, so downstream customer environments need checking too.
- Credentials from infostealer logs and resold initial access.
Until sample analysis is published, treat the entry point as unknown and establish the real path from full log review rather than assumption.
Encryption behavior
Whether Vexy actually encrypts data is not publicly confirmed. Tracker labelling is inconsistent: WatchGuard lists both direct and double extortion, others describe a steal-first, extort-second data broker, and leak-site posts talk about publication rather than decryption.
Prepare for both. If only exfiltration occurred, the work is scoping the leak, meeting notification duties and rotating credentials. If files are encrypted too, the algorithm, whether encryption is intermittent, whether shadow copies were deleted and whether virtualisation was touched must all be measured on the actual samples - conclusions from other families do not transfer.
Assess before you act
Recoverability assessment
A Vexy incident runs along two tracks. We do not pay ransoms and do not negotiate; our work is technical recovery, leak assessment and forensics.
Track 1: data breach impact assessment (the focus of most Vexy cases). Establish what was actually taken, how much and when from egress traffic, cloud storage and transfer logs and file access auditing - rather than accepting leak-site claims. Map the data types to regulatory and contractual notification duties, and rotate domain and service accounts, API keys, certificates and any connection strings inside the stolen files.
Track 2: if files really are encrypted, assess in order of feasibility: public decryptor (none exists) - structural repair (if encryption proves intermittent, database files and virtual disks often retain large intact regions, allowing page-level extraction and rebuilds) - backups and snapshots (offline and offsite backups, storage-layer and hypervisor snapshots usually deliver the highest yield) - unencrypted copies and log replay (recycle bins, endpoint caches, reporting staging databases, transaction logs) - low-level carving (provided writes to the original volumes stop immediately). The achievable ratio depends on whether critical structures were hit, so assessment precedes any commitment.
We commit to a verifiable assessment and a clearly bounded recovery scope. We never claim "100% decryption", and no technique guarantees full recovery.
Our response plan
Hit by Vexy ransomware? What to do
Containment and evidence preservation
Isolate affected hosts and external links and disable suspicious accounts and remote access paths - but do not power off, reboot or clean up suspected malware files. Image or snapshot domain controllers, file servers, backup servers and internet-facing hosts first, and export firewall, VPN, cloud storage and Active Directory logs. Keep three to five original encrypted files and the ransom note if they exist.
Attribution and sample analysis
Because Vexy has no published extension or note, attribution must come from evidence rather than labels: correlate the leak-site post, Tox contact traces, staged tooling and persistence techniques. Where an encryptor sample exists, reverse it to establish the algorithm, encryption granularity and whether shadow copies were destroyed. That finding decides whether the case is a leak assessment or a data recovery job.
Leak scope and recoverability assessment
In parallel: use log and traffic evidence to establish the real data types, volume and time window of the exfiltration, producing the factual basis for notification; and inventory backups, snapshots and unencrypted copies while running sample repairs on critical databases and VMs. The deliverable is a written assessment - what must be reported, which systems restore from backup, which need structural repair, with expected ranges and timelines.
Recovery or response execution
All work happens on images or copies with originals kept read-only. Where only exfiltration occurred, the focus is credential and key rotation, notification, and customer and regulator communication. Where encryption is involved, restore in business priority order - identity and domain services, core databases (ERP, MES, finance), then file and mail systems - with integrity checks and business-side verification after each batch.
Root cause, hardening and handover
Reconstruct the full kill chain: initial access, dwell time, and the timing and channel of exfiltration. Remove backdoors, rogue accounts and scheduled tasks; reset credentials domain-wide and enforce MFA on every remote entry point; reduce the external attack surface; rebuild backups to a 3-2-1 design with immutable copies; and add monitoring across hosting and supply-chain relationships. Close with an incident report and handover checklist, and keep watching the leak site for follow-on posts.
Risk warning
What not to do
- Do not downgrade this to a routine security event just because there is no ransom note and systems still run - in data-theft extortion the damage sits on the leak side, and delay burns notification deadlines.
- Do not power off, reboot or rebuild affected hosts in a hurry; memory and disk artefacts are the primary evidence for scoping the exfiltration.
- Do not download or run any so-called "Vexy decryptor" found online: no public decryptor exists, and such tools are usually follow-on scams or destructive.
- Do not contact the operators through the leak site or Tox on your own, and do not pay. Payment cannot guarantee deletion, and the copies they hold can still be resold or re-extorted.
- Do not reconnect backup media or the backup server to an uncleaned network, and do not restore production before the entry point is confirmed.
- Do not build a recovery plan on unverified press claims such as a "Rust encryptor" - misattribution sends the whole response in the wrong direction.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
Related industries
Manufacturing Ransomware Response and Recovery
Ransomware in manufacturing hits information systems and production cadence at the same time: with ERP down there are no orders, with MES down there is no schedule, and an encrypted drawing library takes the process documentation for an entire product line with it. This page covers the asset profile, recovery priorities and targeted defences.
Retail and E-commerce Ransomware Response
In retail and e-commerce, ransomware translates directly into an inability to sell: order systems, membership, POS and warehouse fulfilment stop together and losses accrue by the hour. This page covers the sector's attack patterns, a recovery order built around the order-to-fulfilment chain, and handling of member data exposure.
Construction and Real Estate Ransomware Response
In construction and real estate the core assets are drawings, models and project documentation — typically scattered across project-site NAS units, shared drives and personal computers with no unified backup. This page covers the sector's threat profile, recovery of drawings and BIM models, and defences for dispersed, multi-project environments.
Similar families
- No public decryptor
Panzer
Panzer is an emerging ransomware-as-a-service operation first seen in August 2026, advertising encryptors for Windows, Linux, VMware ESXi and FreeBSD and running a steal-then-encrypt double-extortion model. Payload-level detail remains scarce and no free decryptor exists.
- No public decryptor
World Leaks
World Leaks is the extortion-only brand Hunters International adopted in January 2025: no encryptor, no renamed files, just data theft backed by a Tor leak site. No new victims have been posted since late July 2026 and the leak site has been unreachable, so the operation currently looks dormant.
- No public decryptor
Silent Ransom Group
Silent Ransom Group (Luna Moth, Chatty Spider, UNC3753) is a Conti-lineage crew that extorts without encrypting anything. Operators impersonate an internal IT helpdesk by phone, walk staff into a remote-access session, take documents out, then press with a clearnet leak site and calls to employees. The FBI flagged in-person intrusions with USB storage in both May 2025 and May 2026.
FAQ
Vexy Frequently asked questions
Are "New Vexy" and "Vexy" the same group?
Yes. Public trackers (ransomware.live, RansomLook, WatchGuard, Breachsense) all record it as Vexy or Vexy Ransomware; "New Vexy" mostly comes from headlines phrased as "new ransomware group Vexy". Either spelling works when searching, but use Vexy in reports and external communication to avoid confusion with other similarly named new families.
Is there a decryptor for files encrypted by Vexy?
No free public decryptor exists, and the family is not listed on No More Ransom. No vendor has published a sample analysis of a Vexy encryptor either, so even whether it encrypts files at all lacks authoritative confirmation. If your files are encrypted, start by identifying the family and build from real samples, then assess backups, structural repair and carving. Never trial unknown tools against original disks.
Our name is on the Vexy leak site but nothing is encrypted - does it matter?
Yes, and the clock is often tighter. The core risk is the data itself: establish from logs and traffic evidence what was taken, how much and when, use that to meet internal, regulatory and contractual notification duties, and rotate the affected accounts, keys and certificates. Note also that leak-site claims are not reliable - they may be inflated, or may be only an initial sample - so conclusions must rest on your own evidence.
We are a hosting or IT service provider - why does Vexy target companies like ours?
Its published victim list leans heavily towards small and mid-sized IT service providers, cloud and hosting companies. The logic is practical: such firms hold data and access credentials for many customers, so one intrusion produces amplified leverage, and their service commitments make downtime and exposure harder to absorb. If this describes you, assess whether customer environments were reached laterally and honour the notification duties in your contracts alongside your own response.
Should organisations in mainland China be concerned about Vexy?
No public report places Vexy against mainland China organisations; known victims cluster in India and Latin America. Two points still matter: overseas subsidiaries, cross-border operations and offshore hosting providers used by Chinese firms sit inside its target space; and emerging crews like this rely on ordinary entry points - remote access without MFA, unpatched edge devices, stolen credentials - so reducing that exposure pays off against any family. We run 24/7 emergency response and can return an initial assessment quickly after remote access is granted.
Sources
- Vexy ransomware group profile — Ransomware.live
- Vexy — RansomLook (leak site status and posts)
- Vexy — WatchGuard Ransomware Tracker
- Vexy ransomware group — Breachsense
- Vexy Ransomware Breach Tracker — GalaxyWarden
- Decryption Tools — No More Ransom (no Vexy entry as of 2026-09-11)
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated