Mallox Ransomware

Description

FortiGuard Labs is aware of recent reports of an uptick of activity in the Mallox ransomware observed in the wild. Reportedly, the Mallox threat actor distributes ransomware via a downloader attached to spam emails by targeting unsecured internet-facing Microsoft SQL servers. Mallox ransomware encrypts files on compromised machines and typically adds a ".mallox" file extension to the affected files.


Why is this Significant?

This is significant because recent reports highlight an increased uptick of Mallox ransomware activities. Ransomware infection causes disruption, damage to daily operations, potential impact to an organization's reputation, and the unwanted destruction or release of personally identifiable information (PII), etc.


What is Mallox Ransomware?

Mallox is a ransomware strain that has been around since 2021 and is also known as Fargo. The ransomware encrypts files on compromised machines and typically adds a ".mallox" file extension to the affected files. Mallox leaves a ransom note titled "FILE RECOVERY.txt" that contains the ransom message, victim's private key, and a TOR site address where victims can contact the attacker. The TOR site also works as a data leak site where information stolen from the victims will be released if ransom payment is not made. At the time of this writing, the leak site listed one company, however previous victims may have been removed.



Ransom note left by Mallox ransomware


Mallox ransomware threat actor reportedly distributes the ransomware via downloader malware attached to spam emails. The threat actor also targets unsecured internet-facing Microsoft SQL servers by attempting to log with a list of username and password combinations.

What is the Status of Protection?
FortiGuard Labs provides the following AV signatures for known Mallox ransomware samples:

  • W32/Filecoder.D181!tr.ransom
  • W32/Filecoder.OJC!tr.ransom
  • W32/Generic.AC.171!t
  • MSIL/Agent.LXR!tr
  • MSIL/Agent.LYC!tr
  • MSIL/Agent.NLO!tr.dldr
  • MSIL/Agent.NZA!tr.dldr
  • MSIL/Agent.OBD!tr.dldr
  • MSIL/Agent.OEY!tr.dldr
  • MSIL/Agent.OFN!tr.dldr
  • MSIL/Agent.OHG!tr.dldr
  • MSIL/GenKryptik.FMRD!tr
  • MSIL/Kryptik.ADHC!tr
  • MSIL/Kryptik.AGYT!tr.ransom
  • MSIL/Kryptik.AHJZ!tr
  • MSIL/Kryptik.DCC!tr
  • PossibleThreat