Mallox ransomware: in-depth analysis and evolution
ID: bcb2d8ab-8ef6-5b6f-a35e-ee63872e0088
STIX ID: report--bcb2d8ab-8ef6-5b6f-a35e-ee63872e0088
Feed Name: Securelist by Kaspersky
This report provides a technical overview of the Mallox ransomware family (active since 2021), its transition into a Ransomware-as-a-Service (RaaS) model with multiple affiliates, detailed analyses of early and recent malware versions (cryptography, encryption, persistence and shutdown/anti-recovery techniques), common infection vectors (RDP/MS SQL/PostgreSQL exploitation, spam, purchased access), observed telemetry spikes, negotiation/data-leak portals used for extortion, and a list of IoCs and defensive recommendations for organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
