Mallox ransomware: in-depth analysis and evolution


Mallox is a sophisticated and dangerous family of malicious software that has been causing significant damage to organizations worldwide.

In 2023, this ransomware strain demonstrated an uptick in attacks, the overall number of discovered Mallox samples exceeding 700. In the first half of 2024, the malware was still being actively developed, with new versions being released several times a month, while the Mallox RaaS affiliate program advertised on dark web forums was seeking new partners. This article aims to provide a comprehensive technical overview of the ransomware and its history.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • XCSSET evolves again: Analyzing the latest updates to XCSSET’s inventory

    September 25, 2025

    Microsoft Threat Intelligence has identified yet another XCSSET variant in the wild that introduces further updates and new modules beyond those detailed in our March 2025 blog post. The XCSSET malware is designed to infect Xcode projects, typically used by software developers, and run while an Xcode project is being built. We assess that this mode ...

  • New LockBit 5.0 Targets Windows, Linux, ESXi

    September 25, 2025

    Trend™ Research has identified and analyzed the source binaries of a new LockBit version in the wild, which is the latest from the group’s activities following the February 2024 law enforcement operation (Operation Cronos) that disrupted their infrastructure. In early September, the LockBit ransomware group reportedly resurfaced for their sixth anniversary, announcing the release of “LockBit ...

  • Co-op digests £80m profit hit from cyber attack

    September 25, 2025

    he Co-operative Group has revealed an £80m hit to half-year profit after a damaging cyber attack earlier this year. The retail and funerals specialist said that it had slumped to a loss in the first half of 2025 after being targeted by a “malicious” cyber attack. Shoppers were faced with empty shelves and issues with payments ...

  • UK: Jaguar Land Rover facing costs of “millions per week” following cyberattack due to a lack of insurance cover

    September 25, 2025

    Jaguar Land Rover could be facing the full financial impact of its recent cyberattack after reportedly failing to secure cyber insurance before the incident struck. The attack, which came to light on September 2025, forced the carmaker to shut down its IT networks and halt production at its three UK factories. The disruption is believed to ...

  • US federal agency breached by hackers using GeoServer exploit

    September 24, 2025

    In mid-July 2024, a threat actor managed to break into a US Federal Civilian Executive Branch (FCEB) agency by exploiting a critical remote code execution (RCE) vulnerability in GeoServer, the government has confirmed. In an in-depth report detailing the incident, the US Cybersecurity and Infrastructure Security Agency (CISA) outlined how the attackers leveraged CVE-2024-36401, a 9.8/10 ...

  • UK: Man arrested in connection with cyber-attack on airports

    September 24, 2025

    A person has been arrested in connection with a cyber-attack which has caused days of disruption at several European airports including Heathrow. The National Crime Agency (NCA) said a man in his forties was arrested in West Sussex “as part of an investigation into a cyber incident impacting Collins Aerospace”. There have been hundreds of flight ...