Weaxor is a ransomware operation assessed to be a rebrand or modified continuation of the Mallox, also known as FARGO, ransomware activity. It has been associated with opportunistic attacks against public-facing servers and has been observed exploiting newly disclosed vulnerabilities for rapid initial access and near-immediate ransomware deployment. Reporting links Weaxor to exploitation of CVE-2025-55182 (React2Shell), with the ransomware launched within roughly a minute of compromise, indicating a highly automated intrusion workflow. Observed tradecraft includes use of remote code execution for initial access, execution of obfuscated PowerShell, deployment of Cobalt Strike for post-exploitation command-and-control, disabling of endpoint protections such as Windows Defender, deletion of shadow copies, and clearing of event logs to hinder recovery and forensic analysis. In the documented React2Shell intrusion, activity was confined to the initially compromised host, with no confirmed lateral movement or data exfiltration. Weaxor is also described as lacking a data leak portal, and available reporting does not show evidence of theft-based extortion as a routine component of its operations. The operation has historical ties to Mallox targeting patterns, including attacks against MS-SQL servers, and has been connected to infrastructure used in broader criminal activity associated with Russian bulletproof hosting ecosystems. Available evidence supports characterization of Weaxor as a financially motivated cyber extortion actor focused primarily on ransomware encryption rather than double-extortion or espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operators of Weaxor (Mallox) ransomware exploiting React2Shell vulnerability for automated ransomware deployment and cyber extortion.
Weaxor is a ransomware operation believed to be a rebrand of the Mallox/FARGO operation, known for opportunistic attacks on public-facing servers, particularly exploiting vulnerabilities like React2Shell for rapid ransomware deployment. The group demands relatively low ransoms and does not engage in double extortion or data exfiltration.
Ransomware group observed with infrastructure/campaign connections to Proton66; uses a Mallox-derived encryptor and demands payment (noted $2,000 in BTC/USDT in the report).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.