Avast released a free decryptor for TargetCompany ransomware, also tracked as Mallox, allowing some victims to recover encrypted files without paying. The tool works by cracking the decryption password from a pair of matching encrypted and original files, a CPU-intensive process that can take tens of hours but only needs to be completed once per affected device; interrupted cracking sessions can also be resumed. Researchers said the ransomware has been active since mid-2021, commonly appending extensions including .mallox, .exploit, .architek, and .brg, and dropping the ransom note HOW TO RECOVER !!.TXT in affected folders.
Technical reporting shows the malware prepares systems for encryption by deleting shadow copies, altering boot and recovery settings, assigning privileges, enumerating drives, and terminating processes that could lock valuable data such as databases and backup-related services. Avast said file encryption uses ChaCha20, with key protection involving Curve25519 and AES-128, while later threat intelligence linked Mallox to a more active double-extortion operation that uses a .NET loader, in-memory payload decryption, victim data exfiltration, and a leak site, with some observed process-killing behavior suggesting possible interest in critical infrastructure and operational technology environments.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
In February 2023, researchers detected the Xollam variant of the TargetCompany ransomware family. Unlike earlier variants that commonly exploited vulnerable Microsoft SQL Server instances, Xollam used spam campaigns with malicious Microsoft OneNote attachments and PowerShell-based reflective loading to deliver its payload.
A TargetCompany/Mallox ransomware variant targeting Microsoft SQL servers was identified. This variant appended the "Fargo" extension to encrypted files.
Avast released a free decryptor for TargetCompany ransomware victims that can recover files under certain circumstances. The tool performs a CPU-intensive password-cracking step that may take tens of hours but only needs to be completed once per affected PC and can resume from saved progress.
A ransomware victim contacted Avast for help after a TargetCompany infection. Avast identified the malware from the encrypted file extension and ransom note.
TargetCompany ransomware was first identified in June 2021 and described as active from that time. Researchers named it for appending the targeted company name as a file extension to encrypted files.
Cyble Research and Intelligence Labs reported a spike in Mallox ransomware samples in the wild, indicating increased activity and rapid spread in recent weeks. The campaign used a 32-bit .NET loader delivered via spam email to fetch, decrypt, and execute the ransomware payload in memory.
A Mallox/TargetCompany ransomware variant targeting HERRCO was observed using the .herrco extension and the ransom note "How to decrypt files.txt." The sample is documented with SHA-256 hash 415321444d2ab732e84ff7acb4739e09827ee2fcc748d0fa1d7504bae1d133a3.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 74 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourceblog.cyble.com
Open sourcesecurityaffairs.co
Open sourcedecoded.avast.io
Open sourcebleepingcomputer.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.