Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

Vexy Ransomware Decryption & Data Recovery

  • Active
  • Medium
  • No public decryptor

Vexy (written as New Vexy by some feeds) is an emerging extortion crew that surfaced in early September 2026. It runs its own Tor leak site and pressures victims with full-leak threats, mostly IT service and hosting providers and manufacturers in India and Latin America. Public technical data is minimal: no confirmed extension, note or decryptor.

First seen
2026-09
File extensions
No public information
Ransom notes
No public information
Affected platforms
No public information

Public information on this family is limited. What follows is compiled from the small amount of verified material available, so please contact us for a sample assessment before you act on it.

Family profile

File extensions
No public information
Ransom notes
No public information
Contact patterns
  • Tor (.onion) leak site (onion name starts with vexy)
  • Tox messenger ID
  • No fixed mail domain observed publicly
Aliases / versions
New Vexy、Vexy Ransomware
First seen
2026-09
Status
Active
Operational status
Newly emerged
Threat level
Medium
Affected platforms
No public information
Tags
  • Emerging
  • Active
  • Extortion-only
Decryptor
No public decryptor

There is no free public decryptor for Vexy. The family is not listed on No More Ransom, and no vendor or law-enforcement agency has released keys or a decryption tool for it.

More fundamentally, as of 2026-09-11 no vendor has published a sample analysis of a Vexy encryptor, so whether its crypto implementation has an exploitable flaw is unknown. If your files are genuinely encrypted, identify the family and build from real encrypted files and the ransom note first, then assess recovery paths - do not run an unverified "Vexy decryptor" against original disks. Tools that appear right after a new brand emerges are frequently follow-on scams or damage file structures.

Sources

Latest activity

  1. About ten days in, Vexy had listed 11 organisations, most of them Indian. RansomLook logs only about one-third uptime for its onion site over 30 days.

    Sources
  2. Indian hosting and cloud provider i2k2 Networks was listed on the Vexy leak site, underlining the crew's focus on small and mid-sized IT and hosting providers.

    Sources
  3. Vexy's Tor leak site was first indexed by public trackers, with the earliest claimed victim (Brazilian manufacturer Engefitas) dated 2 September 2026.

    Sources

Overview

Vexy first appeared on the dark web in early September 2026. ransomware.live and RansomLook began recording its leak site on 3 September, with the earliest claimed attack dated 2 September; by 11 September the trackers listed between 10 and 12 organisations, depending on how each counts. Victims cluster in India (IT services, hosting and cloud, manufacturing, retail), with the rest spread across Brazil, Argentina, Mexico and Ecuador. No public report places Vexy against mainland China organisations.

The caveat matters: public information on this family is very limited. As of 2026-09-11 no major vendor or CERT has published a sample analysis or IOC set for Vexy. Claims circulating in Chinese-language media about a Rust cross-platform encryptor and an affiliate entry fee appear only in secondary write-ups with no vendor analysis or sample behind them; we cannot verify them and do not repeat them as fact. What is confirmed: a dedicated Tor leak site (its onion name starts with vexy; reported uptime varies widely between trackers), Tox as the contact channel, and posts threatening full publication unless the victim makes contact - trackers generally describe the group as stealing data first and extorting second. This page will be updated as reporting matures.

How to identify it

Vexy has no publicly documented extension or ransom note filename, so extension matching cannot identify it. Attribution currently rests on the extortion side: the organisation appears on an .onion leak site whose name starts with vexy, in a post that typically carries a company profile, an attacker-claimed data volume and a sample pack; contact is directed to Tox rather than email; and the wording centres on full publication if the victim does not make contact, with no mention of decryption.

If files are also encrypted, preserve three to five encrypted samples and the original note. That material is first-hand intelligence and must be confirmed by reverse engineering and comparison - do not self-attribute from a "new family" headline, because misattribution leads straight to the wrong recovery plan.

Infection vectors

No public report documents Vexy's initial access or lateral movement. The list below is a triage priority derived from its victim profile (small and mid-sized IT service providers, hosting and cloud companies, manufacturers), not a confirmed kill chain:

  • Internet-exposed remote access without MFA (VPN, RDP, jump hosts) and known vulnerabilities in edge appliances.
  • Managed-service and supply-chain pivots - several victims are themselves IT or hosting providers, so downstream customer environments need checking too.
  • Credentials from infostealer logs and resold initial access.

Until sample analysis is published, treat the entry point as unknown and establish the real path from full log review rather than assumption.

Encryption behavior

Whether Vexy actually encrypts data is not publicly confirmed. Tracker labelling is inconsistent: WatchGuard lists both direct and double extortion, others describe a steal-first, extort-second data broker, and leak-site posts talk about publication rather than decryption.

Prepare for both. If only exfiltration occurred, the work is scoping the leak, meeting notification duties and rotating credentials. If files are encrypted too, the algorithm, whether encryption is intermittent, whether shadow copies were deleted and whether virtualisation was touched must all be measured on the actual samples - conclusions from other families do not transfer.

Assess before you act

Recoverability assessment

A Vexy incident runs along two tracks. We do not pay ransoms and do not negotiate; our work is technical recovery, leak assessment and forensics.

Track 1: data breach impact assessment (the focus of most Vexy cases). Establish what was actually taken, how much and when from egress traffic, cloud storage and transfer logs and file access auditing - rather than accepting leak-site claims. Map the data types to regulatory and contractual notification duties, and rotate domain and service accounts, API keys, certificates and any connection strings inside the stolen files.

Track 2: if files really are encrypted, assess in order of feasibility: public decryptor (none exists) - structural repair (if encryption proves intermittent, database files and virtual disks often retain large intact regions, allowing page-level extraction and rebuilds) - backups and snapshots (offline and offsite backups, storage-layer and hypervisor snapshots usually deliver the highest yield) - unencrypted copies and log replay (recycle bins, endpoint caches, reporting staging databases, transaction logs) - low-level carving (provided writes to the original volumes stop immediately). The achievable ratio depends on whether critical structures were hit, so assessment precedes any commitment.

We commit to a verifiable assessment and a clearly bounded recovery scope. We never claim "100% decryption", and no technique guarantees full recovery.

Our response plan

Hit by Vexy ransomware? What to do

  1. Containment and evidence preservation

    Isolate affected hosts and external links and disable suspicious accounts and remote access paths - but do not power off, reboot or clean up suspected malware files. Image or snapshot domain controllers, file servers, backup servers and internet-facing hosts first, and export firewall, VPN, cloud storage and Active Directory logs. Keep three to five original encrypted files and the ransom note if they exist.

  2. Attribution and sample analysis

    Because Vexy has no published extension or note, attribution must come from evidence rather than labels: correlate the leak-site post, Tox contact traces, staged tooling and persistence techniques. Where an encryptor sample exists, reverse it to establish the algorithm, encryption granularity and whether shadow copies were destroyed. That finding decides whether the case is a leak assessment or a data recovery job.

  3. Leak scope and recoverability assessment

    In parallel: use log and traffic evidence to establish the real data types, volume and time window of the exfiltration, producing the factual basis for notification; and inventory backups, snapshots and unencrypted copies while running sample repairs on critical databases and VMs. The deliverable is a written assessment - what must be reported, which systems restore from backup, which need structural repair, with expected ranges and timelines.

  4. Recovery or response execution

    All work happens on images or copies with originals kept read-only. Where only exfiltration occurred, the focus is credential and key rotation, notification, and customer and regulator communication. Where encryption is involved, restore in business priority order - identity and domain services, core databases (ERP, MES, finance), then file and mail systems - with integrity checks and business-side verification after each batch.

  5. Root cause, hardening and handover

    Reconstruct the full kill chain: initial access, dwell time, and the timing and channel of exfiltration. Remove backdoors, rogue accounts and scheduled tasks; reset credentials domain-wide and enforce MFA on every remote entry point; reduce the external attack surface; rebuild backups to a 3-2-1 design with immutable copies; and add monitoring across hosting and supply-chain relationships. Close with an incident report and handover checklist, and keep watching the leak site for follow-on posts.

Risk warning

What not to do

  • Do not downgrade this to a routine security event just because there is no ransom note and systems still run - in data-theft extortion the damage sits on the leak side, and delay burns notification deadlines.
  • Do not power off, reboot or rebuild affected hosts in a hurry; memory and disk artefacts are the primary evidence for scoping the exfiltration.
  • Do not download or run any so-called "Vexy decryptor" found online: no public decryptor exists, and such tools are usually follow-on scams or destructive.
  • Do not contact the operators through the leak site or Tox on your own, and do not pay. Payment cannot guarantee deletion, and the copies they hold can still be resold or re-extorted.
  • Do not reconnect backup media or the backup server to an uncleaned network, and do not restore production before the entry point is confirmed.
  • Do not build a recovery plan on unverified press claims such as a "Rust encryptor" - misattribution sends the whole response in the wrong direction.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related industries

Similar families

FAQ

Vexy Frequently asked questions

  • Are "New Vexy" and "Vexy" the same group?

    Yes. Public trackers (ransomware.live, RansomLook, WatchGuard, Breachsense) all record it as Vexy or Vexy Ransomware; "New Vexy" mostly comes from headlines phrased as "new ransomware group Vexy". Either spelling works when searching, but use Vexy in reports and external communication to avoid confusion with other similarly named new families.

  • Is there a decryptor for files encrypted by Vexy?

    No free public decryptor exists, and the family is not listed on No More Ransom. No vendor has published a sample analysis of a Vexy encryptor either, so even whether it encrypts files at all lacks authoritative confirmation. If your files are encrypted, start by identifying the family and build from real samples, then assess backups, structural repair and carving. Never trial unknown tools against original disks.

  • Our name is on the Vexy leak site but nothing is encrypted - does it matter?

    Yes, and the clock is often tighter. The core risk is the data itself: establish from logs and traffic evidence what was taken, how much and when, use that to meet internal, regulatory and contractual notification duties, and rotate the affected accounts, keys and certificates. Note also that leak-site claims are not reliable - they may be inflated, or may be only an initial sample - so conclusions must rest on your own evidence.

  • We are a hosting or IT service provider - why does Vexy target companies like ours?

    Its published victim list leans heavily towards small and mid-sized IT service providers, cloud and hosting companies. The logic is practical: such firms hold data and access credentials for many customers, so one intrusion produces amplified leverage, and their service commitments make downtime and exposure harder to absorb. If this describes you, assess whether customer environments were reached laterally and honour the notification duties in your contracts alongside your own response.

  • Should organisations in mainland China be concerned about Vexy?

    No public report places Vexy against mainland China organisations; known victims cluster in India and Latin America. Two points still matter: overseas subsidiaries, cross-border operations and offshore hosting providers used by Chinese firms sit inside its target space; and emerging crews like this rely on ordinary entry points - remote access without MFA, unpatched edge devices, stolen credentials - so reducing that exposure pays off against any family. We run 24/7 emergency response and can return an initial assessment quickly after remote access is granted.