logo

Mallox ransomware: in-depth analysis and evolution

ID: bcb2d8ab-8ef6-5b6f-a35e-ee63872e0088

STIX ID: report--bcb2d8ab-8ef6-5b6f-a35e-ee63872e0088

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2024-09-04

Date Updated: 2026-04-29

Author: Fedor Sinitsyn, Yanis Zinchenko

...
...

This report provides a technical overview of the Mallox ransomware family (active since 2021), its transition into a Ransomware-as-a-Service (RaaS) model with multiple affiliates, detailed analyses of early and recent malware versions (cryptography, encryption, persistence and shutdown/anti-recovery techniques), common infection vectors (RDP/MS SQL/PostgreSQL exploitation, spam, purchased access), observed telemetry spikes, negotiation/data-leak portals used for extortion, and a list of IoCs and defensive recommendations for organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.