RansomExx surfaced on the tracker this week with two claims tied to a single victim, Go2Joy, a Vietnamese hospitality and tourism platform, suggesting a narrow, opportunistic burst of activity rather than a sustained campaign. The group is described in open-source reporting as active since mid-2020 and sharing code lineage with the Defray777 family, though that pedigree is unverified and should be treated as background context only. Historically catalogued RansomExx techniques include disabling security tooling prior to encryption and using targeted, manually-deployed payloads rather than mass-spray infection, consistent with a low-volume, high-precision operating style. Given the current sample size of two claims against one target, geographic and sector concentration in Vietnam and hospitality cannot yet be read as an established pattern, only as this week's observed footprint. No additional claimed victims have been logged in the prior 30 days beyond this single incident.