Mallox ransomware: in-depth analysis and evolution


Mallox is a sophisticated and dangerous family of malicious software that has been causing significant damage to organizations worldwide.

In 2023, this ransomware strain demonstrated an uptick in attacks, the overall number of discovered Mallox samples exceeding 700. In the first half of 2024, the malware was still being actively developed, with new versions being released several times a month, while the Mallox RaaS affiliate program advertised on dark web forums was seeking new partners. This article aims to provide a comprehensive technical overview of the ransomware and its history.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • A Ransomware Group Is Claiming They’ve Breached Sony’s Systems And Stolen Data

    September 27, 2023

    Although the claims of a data breach are still unverified, Sony has publicly acknowledged the situation and issued a statement to IGN which simply reads, “We are currently investigating the situation, and we have no further comment at this time.” It looks like Sony may have been victim of a breach resulting in the collection of ...

  • ASEAN, China, and UNODC agree to a plan of action to address criminal scams in Southeast Asia

    September 26, 2023

    Senior officials from ASEAN, China and United Nations Office on Drugs and Crime (UNODC) have agreed to address transnational organized crime and trafficking in persons associated with casinos and scams. “Trafficking in persons connected to casinos and scam operations run by organized crime has mushroomed across Southeast Asia, particularly in the Mekong” remarked Jeremy Douglas, UNODC ...

  • Dusting for fingerprints: ShadowSyndicate, a new RaaS player?

    September 26, 2023

    The Ransomware-as-a-Service (RaaS) market is a fast-moving one. Prominent RaaS or affiliate groups can form, wreak havoc, and disband all within a short period of time. In this blog, Group-IB researchers will detail what they believe to be a new RaaS group that appears to operate differently from the rest: Enter ShadowSyndicate. What is unusual about ...

  • APT and financial attacks on industrial organizations in H1 2023

    September 25, 2023

    This summary provides an overview of reports of APT and financial attacks on industrial enterprises that were disclosed in H1 2023, as well as related activities of groups that have been observed attacking industrial organizations and critical infrastructure facilities. For each topic, Kaspersky researchers have sought to summarize the key facts, findings, and conclusions of the ...

  • China to impose severe punishment on crimes of cyberbullying, defamation offenses, fabricating sexual topics

    September 25, 2023

    China on Monday released guidelines to severely punish cyberspace violations that target minors, involve paid posters, fabricate “sexual” topics and use artificial intelligence to disseminate illegal information. The guidelines on punishing crimes of cyberspace violence in accordance with laws were jointly issued by China’s Supreme People’s Court, China’s Supreme People’s Procuratorate and China’s Ministry of Public ...

  • UK: Reported cyber security breaches increase threefold for financial services firms

    September 25, 2023

    Cyber security breaches for UK financial services firms have increased threefold from the years of 2021-2022 and 2022-2023, with the highest – reportedly – being in the pensions sector. New research by the international law firm RPC shows that the amount of reports of cyber security breaches to the Information Commissioners Office (ICO) has increased from ...