SEXi, also referred to as APT INC following a reported rebrand, is a ransomware operation known for targeting VMware ESXi environments and, in some intrusions, Windows systems alongside Linux-based virtualization infrastructure. The group has been associated with financially motivated attacks against organizations running ESXi, including cases involving unsupported ESXi versions. A notable characteristic of SEXi is its use of different ransomware codebases depending on the victim platform. Operations attributed to the group have used a Babuk-derived encryptor for Linux and ESXi systems and a LockBit-derived encryptor for Windows systems. This multi-platform approach indicates an emphasis on maximizing impact across mixed enterprise environments, particularly virtualized infrastructure. SEXi has been described as relying on leaked ransomware source code rather than bespoke malware development. Reporting has highlighted operational traits suggesting a comparatively less mature or less professional tradecraft than top-tier ransomware programs, including the reuse of the same Session messenger contact identifier across multiple victims and the apparent absence of a dedicated leak site in observed cases. Even so, the group remains operationally significant because leaked ransomware families such as Babuk and LockBit can still be highly effective when paired with focused targeting of ESXi infrastructure. The actor has been linked to attacks using Session for victim communications and has been mentioned alongside other ransomware groups that also used Session. The group’s targeting of VMware ESXi aligns with a broader trend in ransomware operations toward disrupting virtualized server estates to increase leverage over victims. Under the APT INC name, the group has continued attacks centered on ESXi systems. Known aliases include SEXi, sexi_ransomware_group, and APT INC. High-confidence reporting supports describing the actor as a ransomware group focused on ESXi-centric extortion operations rather than as a confirmed nation-state threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group mentioned as using the Session messaging service in attacks.
Ransomware group focused primarily on ESXi environments, deploying separate Linux and Windows variants built from leaked Babuk and LockBit code. The group appears comparatively unprofessional and uses Session for victim contact instead of a TOR leak site.
SEXi Ransomware Group (now APT INC) targets VMware ESXi servers and Windows systems using Babuk and LockBit 3 encryptors, demanding ransoms and encrypting data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.