Mallox ransomware: in-depth analysis and evolution


Mallox is a sophisticated and dangerous family of malicious software that has been causing significant damage to organizations worldwide.

In 2023, this ransomware strain demonstrated an uptick in attacks, the overall number of discovered Mallox samples exceeding 700. In the first half of 2024, the malware was still being actively developed, with new versions being released several times a month, while the Mallox RaaS affiliate program advertised on dark web forums was seeking new partners. This article aims to provide a comprehensive technical overview of the ransomware and its history.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • Texas-based care provider HMG Healthcare says hackers stole unencrypted patient data

    January 10, 2024

    Texas-based care provider HMG Healthcare has confirmed that hackers accessed the personal data of residents and employees, but says it has been unable to determine what types of data were stolen. HMG Healthcare is headquartered in The Woodlands, Texas, and provides a range of services, including memory care, rehabilitation, and assisted living. HMG’s website says it ...

  • Thailand: Elderly to get anti-scam education as cybercrime explodes

    January 10, 2024

    Alarmed by research indicating that the elderly are the most vulnerable to fraudsters, Thailand’s Ministry of Social Development and Human Security and CIB cybercrime investigators will collaborate with partners to provide digital literacy to senior people nationwide. The minister, Varawut Silpa-archa, stated that more than 13 million people, or almost 20% of the Thai population, are ...

  • SEC says ‘compromised’ account to blame for tweet approving Bitcoin ETF

    January 10, 2024

    The Securities and Exchange Commission (SEC) said Tuesday that a post sent from the agency’s account on the social platform X/Twitter announcing the approval of a long-awaited bitcoin exchange-traded fund was “unauthorized”, and that the agency’s account had been “compromised”. The price of bitcoin briefly spiked more than $1,000 after the post on X claimed: “The ...

  • AI aids nation-state hackers but also helps US spies to find them, says NSA cyber director

    January 9, 2024

    Nation state-backed hackers and criminals are using generative AI in their cyberattacks, but U.S. intelligence is also using artificial intelligence technologies to find malicious activity, according to a senior U.S. National Security Agency official. “We already see criminal and nation state elements utilizing AI. They’re all subscribed to the big name companies that you would expect ...

  • Fidelity National Financial says hackers stole data on 1.3 million customers

    January 9, 2024

    Real estate services giant Fidelity National Financial (FNF) has confirmed hackers stole data on 1.3 million of its customers during a November cyberattack that knocked the company offline for a week. FNF said in a filing Tuesday with federal regulators: “We determined that an unauthorized third-party accessed certain FNF systems, deployed a type of malware that ...

  • Kenya Airways suffers passenger data breach in cyber attack

    January 9, 2024

    Cybercriminals attacked Kenya Airways’ (KQ) information systems and obtained sensitive information, including contact details and identification documents, of passengers and staff of the airline, an authoritative source at KQ has confirmed. The cyber attack, which occurred late last month, led to unauthorised access to police investigation reports, phone numbers, email addresses, and passports of an unspecified ...