Weaxor is a Windows ransomware family first observed in late 2024 and widely assessed as a rebrand or successor of the Mallox, also known as FARGO or TargetCompany, ransomware operation. It has been associated with financially motivated intrusion activity and has been described in some reporting as operating in a ransomware-as-a-service model, while other reporting has not confirmed a public RaaS presence. The malware has primarily targeted enterprise environments, with a particular focus on Microsoft SQL Server deployments that are misconfigured, internet-exposed, or protected by weak administrative credentials. It has also been deployed opportunistically against vulnerable public-facing servers through exploitation of remote code execution flaws such as CVE-2025-55182.
Observed intrusion chains show Weaxor operators abusing SQL Server features including xp_cmdshell and OLE Automation Procedures to obtain operating system command execution from the database service context. In other cases, attackers gained initial access by exploiting React2Shell and rapidly progressed to ransomware deployment. Post-access activity has included heavily obfuscated PowerShell loaders, AMSI bypasses, staged payload delivery, and in-memory execution of Cobalt Strike Beacon. The malware chain has used dynamic API resolution, WinINet-based communications, and process masquerading or injection into legitimate Microsoft SQL Server tooling to reduce detection.
The final ransomware payload encrypts files and appends a distinctive extension associated with the family. Technical analysis has linked the encryptor to a custom ChaCha20-based implementation rather than reliance on standard Windows cryptographic APIs. Weaxor operators have also been observed clearing Windows event logs and deleting shadow copies to hinder forensic reconstruction and recovery. In incidents tied to exploitation of public-facing applications, deployment has been notably fast, with beacon installation, security-control tampering, and ransomware execution occurring within minutes or less. Available reporting does not consistently show data theft or broad lateral movement as a defining characteristic, and some observed cases were limited to the initially compromised host.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
S-RM has responded to an incident where a threat actor used the recently disclosed critical vulnerability known as React2Shell (CVE-2025-55182) to gain access to a corporate network and deploy ransomware. | The specific ransomware payload we observed was a strain called Weaxor, which was first detected in late 2024. Weaxor is reported to be a rebrand of Mallox ransomware strain.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Weaxor est le successeur de Mallox ransomware, rebrandé fin 2024 pour contourner les profils de détection. Il opère en tant que RaaS (Ransomware-as-a-Service) et cible spécifiquement les serveurs de bases de données d’entreprise, notamment les déploiements Microsoft SQL Server mal configurés ou exposés avec des mots de passe administrateurs faibles.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
During our investigation, we confirmed that the attacker enabled xp_cmdshell and OLE Automation Procedures, allowing SQL Server to execute operating system commands.
Payload capturé via PowerShell Script Block Logging (Event ID 4104) ... Déobfuscation via Invoke-Expression (IEX) ... Téléchargement du payload de second niveau : update.exe via System.Net.WebClient
Routine de déchiffrement XOR personnalisée ... Données encodées en tableaux de bytes bruts pour contourner la détection par signature ... second stager : inversion de tableau + décalage César (+3 par byte)
Masquerading : injection dans C:\Program Files (x86)\Microsoft SQL Server\120\Tools\Binn\SQLPS.exe (binaire Microsoft signé)
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this malware family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.