• News/
  • https://www.bleepingcomputer.com/news/security/hosting-firms-vmware-esxi-servers-hit-by-new-sexi-ransomware/

Hosting firm's VMware ESXi servers hit by new SEXi ransomware

BleepingComputer
·
Lawrence Abrams
·
Published Apr 3, 2024
·
Updated

Update 4/5/24: More information added about discovered Windows encryptors. Chilean data center and hosting provider IxMetro Powerhost has suffered a cyberattack at the hands of a new ransomware gang known as SEXi, which encrypted the company's VMware ESXi servers and backups. PowerHost is a data center, hosting, and interconnectivity company with locations in the USA, South America, and Europe. On Monday, PowerHost's Chile division, IxMetro, warned customers that it suffered a ransomware attack early Saturday morning that encrypted some of the company's VMware ESXi servers that are used to host virtual private servers for customers. Customers hosting their websites or services on these servers are currently down as the company attempts to restore terabytes of data from backups. In the latest update, PowerHost apologized to customers, warning that it may not be possible to restore servers as the backups have also been encrypted. When attempting to negotiate with the threat actors to receive a decryption key, the ransomware gang demanded two bitcoins per victim, which PowerHost's CEO says would equal $140 million. For VPS customers impacted by the attack and who still have their website content, the company is offering to set up a new VPS so that customers can bring their sites back online. According to CronUp cybersecurity researcher Germán Fernández, PowerHost was attacked using a new ransomware that appends the .SEXi extension and drops ransom notes named SEXi.txt. The know...

Read full article

Affected Software

1 affected component
VMware ESXi
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a cyberattack on IxMetro Powerhost by a ransomware group known as SEXi, which targeted their VMware ESXi servers.

2

What security implications are discussed?

The article highlights the serious threat of ransomware attacks on hosting providers and the potential for data loss and system downtime.

3

What products or software are affected?

The affected software mentioned in the article is VMware ESXi.

4

Who is the target of the SEXi ransomware attack?

The target of the SEXi ransomware attack is the Chilean data center and hosting provider IxMetro Powerhost.

5

What additional information was added in the update on 4/5/24?

The update provided more information about recently discovered Windows encryptors related to the SEXi ransomware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203