VORANT. Threat Intelligence Sign in Get the full feed

Emperador group lists Nexbex Solutions as victim

high threat technology

Extortion group 'Emperador' claims theft of 600MB of client data and 10GB+ source code from Indian software firm Nexbex Solutions.

Ransomware.live's tracking of leak-site activity has surfaced a listing attributed to a group identified as 'Emperador' claiming to have compromised Nexbex Solutions Private Limited, a small Kerala, India-based software engineering and mobile app development firm incorporated in 2023. The threat actor claims access to the company's client databases (approximately 600MB, containing names, emails, phone numbers and addresses) as well as source code for more than 200 client projects (10GB+ and reportedly growing). The post lists a number of the victim's own domains and subdomains (e.g., club7ms.com, rayssportsnetwork.com, hwzthat.com and various staging/admin subdomains), which appear to be identifiers of the affected client projects and infrastructure rather than attacker-controlled infrastructure.

No technical details on the intrusion vector, exploited vulnerability, or malware used are provided in this listing, so it is not possible to confirm the initial access method or whether ransomware encryption (as opposed to pure data theft/extortion) was involved. This appears consistent with a double-extortion leak-site posting rather than a disclosed technical compromise chain.

Given the victim's small size and the absence of corroborated technical detail, this represents a routine data-extortion listing rather than a large-scale or high-impact incident. Organizations using Nexbex Solutions as a vendor, or with data held by the firm's SME/retail/e-commerce client base, should monitor for potential exposure of customer PII and validate whether any of their own client data was among the impacted records.

Mentioned in this report

Threat actors emperador

Source reporting: https://www.ransomware.live/id/TmV4YmV4IFNvbHV0aW9ucyBQcml2YXRlIExpbWl0ZWRAZW1wZXJhZG9y

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free