Update 4/5/24: More information added about discovered Windows encryptors. Chilean data center and hosting provider IxMetro Powerhost has suffered a cyberattack at the hands of a new ransomware gang known as SEXi, which encrypted the company's VMware ESXi servers and backups. PowerHost is a data center, hosting, and interconnectivity company with locations in the USA, South America, and Europe. On Monday, PowerHost's Chile division, IxMetro, warned customers that it suffered a ransomware attack early Saturday morning that encrypted some of the company's VMware ESXi servers that are used to host virtual private servers for customers. Customers hosting their websites or services on these servers are currently down as the company attempts to restore terabytes of data from backups. In the latest update, PowerHost apologized to customers, warning that it may not be possible to restore servers as the backups have also been encrypted. When attempting to negotiate with the threat actors to receive a decryption key, the ransomware gang demanded two bitcoins per victim, which PowerHost's CEO says would equal $140 million. For VPS customers impacted by the attack and who still have their website content, the company is offering to set up a new VPS so that customers can bring their sites back online. According to CronUp cybersecurity researcher Germán Fernández, PowerHost was attacked using a new ransomware that appends the .SEXi extension and drops ransom notes named SEXi.txt. The know...
Hosting firm's VMware ESXi servers hit by new SEXi ransomware
BleepingComputer
·Lawrence Abrams
·Published Apr 3, 2024
·Updated
Affected Software
1 affected component
VMware ESXi
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a cyberattack on IxMetro Powerhost by a ransomware group known as SEXi, which targeted their VMware ESXi servers.
2
What security implications are discussed?
The article highlights the serious threat of ransomware attacks on hosting providers and the potential for data loss and system downtime.
3
What products or software are affected?
The affected software mentioned in the article is VMware ESXi.
4
Who is the target of the SEXi ransomware attack?
The target of the SEXi ransomware attack is the Chilean data center and hosting provider IxMetro Powerhost.
5
What additional information was added in the update on 4/5/24?
The update provided more information about recently discovered Windows encryptors related to the SEXi ransomware.