Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

LIBRERIA SANTA FE A P S SRL

lsf.com.ar

Group Vexy Ransomware New Group
Discovered 2026-09-07 08:22 UTC
Est. attack date 2026-09-07
Country AR
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation
Data exfiltrated 24.2GB
This is an emerging group, so this claim should be treated with caution until independently verified.

Description:

LSF (Librería Santa Fe) is a bookstore based in Buenos Aires, Argentina, with multiple branches across the city (CABA). It offers a wide selection of both national and imported books across various genres and authors. The store provides an easy online shopping experience where customers can browse and purchase titles with just a few clicks. It also maintains an active social media presence on Instagram (@libreriasantafe) to share news, promotions, and updates. Visitors are welcome to visit their physical locations in person.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 571

Third Party Employee Credentials: 0


External Attack Surface: 15


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • alt3.aspmx.l.google.com. Google Workspace
  • alt4.aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
TXT Records
  • v=spf1 include:_spf.tap-commerce.com include:mxsmtp.sendpulse.com include:spf.myperfit.com include:_spf.google.com +a +mx ~all
  • facebook-domain-verification=rmi13p3zm6cjlqz98v5pwqyusg4emr
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.