Mallox is an enterprise-focused ransomware-as-a-service operation active since at least June 2021. It is also tracked under names including TargetCompany, Fargo, Xollam, Bozon, and Mawahelper. The operation evolved from a private ransomware group into a selective affiliate program in 2022, reportedly recruiting Russian-speaking affiliates and using affiliate identifiers to track operator activity. Documented affiliate or operator handles include maestro, hiervos, admin, vampire, and panda. Mallox is strongly associated with initial access through exposed or weakly secured Microsoft SQL Server environments, including brute-force attacks against MSSQL credentials, abuse of SQL Server features such as CLR assemblies, xp_cmdshell, and OLE automation, and exploitation of unpatched vulnerabilities. In some intrusions, Mallox operators or affiliates have used loaders such as PureCrypter or custom .NET loaders to decrypt and execute ransomware payloads in memory. Observed post-compromise activity includes persistence through remote access software, credential theft with Mimikatz, network reconnaissance and scanning, lateral movement using created accounts or remote access protocols, and data exfiltration with legitimate tools such as FileZilla. Mallox ransomware commonly disables recovery mechanisms, deletes shadow copies, stops services and applications that could interfere with encryption, and gathers victim system information for registration with operator-controlled infrastructure. The malware has been observed checking language or regional settings to avoid execution in Russian-speaking environments. Mallox conducts double extortion, combining file encryption with theft of victim data and publication threats through a leak site. Victim communications may include private chat portals and escalating pressure tactics. Reporting also indicates at least one Mallox-affiliated Linux variant was built from a modified Kryptina ransomware platform, illustrating the operation’s use of commoditized tooling alongside its Windows-focused tradecraft. Victimology indicates a preference for larger organizations, with guidance to affiliates to target companies above a revenue threshold while avoiding some sectors such as hospitals, government, and education. Reported targeting has included organizations in the United States, United Kingdom, Canada, Australia, and Germany, and activity has also been observed affecting industrial environments. Mallox should be regarded as a financially motivated cybercriminal ransomware ecosystem rather than a state-sponsored espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operation distributing Mallox ransomware, primarily gaining access via vulnerable MS-SQL servers, brute-force and weak credentials, and conducting both single-server ransomware deployments and broader double-extortion intrusions.
Associated with a staging server leak that revealed how the Kryptina platform was adapted for enterprise ransomware attacks, including extending operations into Linux and cloud environments.
Ransomware operation that began as a private group and later launched an affiliate program. It restricts participation to Russian-speaking, experienced affiliates and conducts big game hunting against larger organizations while excluding hospitals and educational institutions.
Enterprise-focused ransomware-as-a-service operation whose affiliates used a modified Kryptina-based Linux ransomware variant ('Mallox v1.0') and Windows droppers/tools. The content says Mallox operators opportunistically target timely vulnerabilities such as MSSQL Server and commonly use brute force attacks for initial access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.