SEXi ransomware encrypted IxMetro PowerHost's ESXi servers and its backups

Organization
IxMetro PowerHost
Exploit
Ransomware
Industry
Hosting and Data Centers

IxMetro PowerHost, the Chilean arm of hosting and data centre provider PowerHost, was hit by ransomware early on Saturday, March 30, 2024. The company warned customers on the following Monday that attackers had encrypted VMware ESXi servers used to run virtual private servers for its clients.

The strain had not been seen before. It appended the .SEXi extension to encrypted files and left ransom notes named SEXi.txt, a play on the name of the ESXi hypervisor, and researchers linked it to leaked Babuk source code. The attackers reached the company's backups as well as its production servers, and PowerHost told customers it might not be possible to restore the affected machines.

Chief executive Ricardo Rubem said the attackers demanded two bitcoin for each affected customer, which he put at roughly $140 million in total. He said the company would not pay, citing consistent advice from law enforcement agencies that criminals simply disappear after payment in more than 90 percent of cases.

PowerHost said it was working with international security agencies to analyse the attack, apologised to customers and offered to provision new virtual private servers for anyone who still held their own copy of their site content. Customers whose data existed only on the encrypted servers were left without a clear recovery path.

Sources