Skip to content
Detecteam
  • CompanyExpand
    • Founders Story
    • The Team
  • ProductExpand
    • About Us
  • SolutionsExpand
    • Use Cases
  • ResourcesExpand
    • Detecteam Blogs
    • Contact Us
Twitter Linkedin
Detecteam
Blog · Scenario

Mallox Ransomware

Avatar photoByDetecteam 2023-07-262023-07-26

TLP

TLP CLEAR

Author

Jordi M. Lobo

Summary

Mallox is a ransomware strain that targets Microsoft Windows systems and has been active since June 2021. Recently, Unit 42 researchers observed a significant increase in Mallox ransomware activities, with a rise of almost 174% compared to the previous year. The group exploits unsecured MS-SQL servers as a penetration vector to compromise victims’ networks. They employ brute force attacks, data exfiltration, and network scanners to distribute the ransomware. Mallox follows the double extortion trend, stealing data before encrypting files and threatening to publish it on a leak site to pressure victims to pay the ransom.

DATA

windows_sysmon.xml_-1Download

TIMELINE

CATEGORY

Ransomware

references

  • https://unit42.paloaltonetworks.com/mallox-ransomware/
  • https://www.hivepro.com/wp-content/uploads/2022/12/Mallox-Ransomware-is-Ramping-up-its-Operation_TA2022300.pdf
  • https://blog.cyble.com/2022/12/08/mallox-ransomware-showing-signs-of-increased-activity/

MITRE ATT&CK

Post Tags: #T1018 - Remote System Discovery#T1027 - Obfuscated Files or Information#T1059.001 - Command and Scripting Interpreter: PowerShell#T1082 - System Information Discovery#T1110.001 - Brute Force: Password Guessing#T1486 - Data Encrypted for Impact#T1490 - Inhibit System Recovery
Avatar photo
Detecteam
X

Detecteam is transforming cybersecurity detection from static rule-writing to autonomous, continuous validation. Our REFLEX platform automates the detection lifecycle—building, testing, validating and deploying detections in minutes, not months. We help enterprises maximize ROI on existing tools, close high-risk detection gaps faster, and scale security outcomes without scaling headcount. This is the future of detection-as-code, and we’re leading it.

CONTACT US

Detecteam Inc.
300 Lenora Street PMB 659
Seattle, WA 98121 USA
+1 (650) 542-0831
sales@detecteam.com

  • Privacy Policy

SOCIAL MEDIA

Twitter Linkedin
OUR NEWSLETTER

Check your inbox or spam to confirm your subscription.

© 2025 Detecteam Inc. All Rights Reserved.

  • Company
    • Founders Story
    • The Team
  • Product
    • About Us
  • Solutions
    • Use Cases
  • Resources
    • Detecteam Blogs
    • Contact Us
Search