TargetCompany is a financially motivated ransomware operation active since at least mid-2021 and commonly associated with the Mallox ransomware family. It has also been referred to as FARGO and Tohnichi, and late reporting links a subsequent rebrand or successor operation under the name Weaxor. The group has conducted extortion campaigns against multiple organizations and has operated as a ransomware-as-a-service ecosystem. TargetCompany is notable for targeting enterprise database infrastructure, particularly Microsoft SQL Server environments that are misconfigured, internet-exposed, or protected by weak administrator credentials. Reported intrusion activity includes abuse of SQL Server functionality for command execution, including xp_cmdshell and OLE Automation Procedures, with alternative execution paths through SQL Agent jobs, CLR assemblies, or SQL injection. Post-compromise tradecraft includes use of obfuscated PowerShell loaders, AMSI bypass, staged payload delivery, and deployment of Cobalt Strike Beacon. Observed malware behavior also includes dynamic API resolution, in-memory payload staging, process masquerading through legitimate Microsoft SQL Server tooling, and clearing of Windows event logs for defense evasion. The ransomware payload has been reported to encrypt files using a custom ChaCha20-based routine. TargetCompany has also expanded beyond Windows-focused operations: a Linux variant targeting VMware ESXi environments has been observed, indicating a shift toward virtualization infrastructure. That variant reportedly used shell-script-based privilege escalation and data exfiltration prior to encryption, consistent with extortion-oriented ransomware operations. Overall, TargetCompany is best characterized as a ransomware and extortion actor focused on enterprise environments, with particular emphasis on database servers and, more recently, ESXi systems. Its known aliases and related branding include Mallox, FARGO, Tohnichi, and the later Weaxor designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operator behind Weaxor, a rebrand/successor of Mallox, targeting enterprise database servers—especially exposed or weakly secured Microsoft SQL Server deployments—for ransomware execution and file encryption.
TargetCompany is known for conducting ransomware attacks.
TargetCompany is a ransomware group that has evolved to target Linux systems and VMware ESXi environments, using custom scripts for privilege escalation, payload delivery, and data exfiltration. Historically focused on database attacks in East Asia, they have expanded their operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.