Quick Summary
AllegedExecutive Summary
Vexy Ransomware claimed Groupe Proxitel, a telecommunications and technology company based in Timor-Leste, on its dark web portal on September 29, 2026. This listing was identified via SOCRadar’s Dark Web Monitoring service. Groupe Proxitel’s sector and location align with Vexy’s typical targeting patterns, which often include technology and telecom firms in developing markets. Over the preceding 60 days, Vexy Ransomware has listed 16 other victims, primarily targeting entities in India, Brazil, and Timor-Leste. The dominant industries exploited by the group are Technology, Retail & E-Commerce, and Manufacturing. Recent victims within the technology and telecommunications sector, such as Strad Solutions, i2k2 Networks, Logar Network Solutions, and Majani Insurance Brokers, further illustrate this pattern. Groupe Proxitel’s inclusion fits within Vexy’s established modus operandi of targeting organizations in these specific industries and geographic regions.
Technical Analysis
SOCRadar’s stealer-log telemetry detected a significant exposure for proxi[.]tel, with 25 records associated with four corporate email addresses. The data spans July through September 2026, with a concentration of entries in late September, immediately preceding the ransomware group’s claim. The identified platforms are a significant concern, including Microsoft 365 identity infrastructure (login.microsoftonline.com), the Acronis backup and disaster-recovery platform, the BitTitan mailbox migration and management service, and the Synology NAS/storage management system, as well as LogMeIn remote-access tooling. One record pertains to employee credentials on an organization-controlled system, while the remaining 23 relate to corporate users on third-party platforms. While the stealer-log data does not definitively confirm the use of these compromised credentials by Vexy Ransomware, the timing and concentration of the findings in late September make a correlation difficult to dismiss. The presence of credentials for backup platforms like Acronis and BitTitan is particularly alarming, as ransomware operators frequently target recovery infrastructure to impede data restoration efforts. The combination of cloud identity access, backup administration tools, and remote access capabilities presents a comprehensive set of potential entry points for attackers. Organizations should prioritize auditing access logs for Acronis and BitTitan, followed by reviewing LogMeIn session history. All four identified corporate email accounts should be treated as compromised, and their credentials must be rotated immediately.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.