Mallox Ransomware Variant Targets Privileged VMWare ESXi Environments
ID: a0ee5e27-314a-50c5-82a4-34c1b7b12779
STIX ID: report--a0ee5e27-314a-50c5-82a4-34c1b7b12779
Feed Name: Dark Reading
Date Published: 2024-06-06
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Mallox (TargetCompany) has deployed a new Linux ransomware variant targeting VMware ESXi hosts that only executes when run with administrative privileges and if the system name indicates an ESXi hypervisor ("vmkernel"). The variant uses a custom shell script to download and run the payload, drops TargetInfo.txt (exfiltrated to two separate servers), encrypts files appending ".locked" and drops a ransom note (HOW TO DECRYPT.txt), and deletes the payload after execution to hinder response; Trend Micro attributes the activity to a Mallox affiliate and recommends MFA, robust backups (3-2-1), and regular patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
