RegistroCiberVE
DirectoryStatisticsThreat actorsTargetsAbout
All threat actors
Threat actor
RA

RansomEXX

RansomEXX is a data-ransom operation that emerged in mid-2020 and is known for targeting corporate networks worldwide. It uses double extortion: it extracts sensitive data before encrypting systems and threatens to publish it if its demands are not met.

Incidents
1
High impact
0
First seen
Dec 21, 2024
Latest seen
Dec 21, 2024

Top targets

Grupo Vargas
1

Linked incidents

Ransomware Dec 21, 2024

RansomEXX Claims Responsibility for Attack on Grupo Vargas

The Venezuelan pharmaceutical company Grupo Vargas and its subsidiaries (Laboratorios Vargas, Zuoz Pharma, and Genérico de Calidad) were the target of a ransomware attack attributed to the RansomEXX group, with the estimated date of the attack around December 21, 2024. Around March 4, 2025, RansomEXX listed the victim on its extortion leak site, claiming approximately 37.6 GB of confidential business data (according to the actor, divided into 26 parts). The 37.6 GB figure is corroborated by ransomware trackers (ransomware.live, ransomlook.io); the division into 26 parts comes from the actor’s own listing and has not been independently verified. It is unclear whether the company suffered any financial losses, and there has been no official public acknowledgment of the incident by the Vargas Group.

Grupo Vargas

Actor profile

Actor type
Criminal
Actor form
Group
Motivation
Financial
Known malware
ransomexxsecuestro de datos

Known aliases

RansomEXX v2
RegistroCiberVE

Cybersecurity incidents in Venezuela, with verifiable evidence.

Explore

  • Directory
  • Statistics
  • Threat actors
  • Targets

Project

  • About

Made by Kevin Bravo

© 2026 RegistroCiberVE