logo

Mallox Ransomware Variant Targets Privileged VMWare ESXi Environments

ID: a0ee5e27-314a-50c5-82a4-34c1b7b12779

STIX ID: report--a0ee5e27-314a-50c5-82a4-34c1b7b12779

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-06-06

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Mallox (TargetCompany) has deployed a new Linux ransomware variant targeting VMware ESXi hosts that only executes when run with administrative privileges and if the system name indicates an ESXi hypervisor ("vmkernel"). The variant uses a custom shell script to download and run the payload, drops TargetInfo.txt (exfiltrated to two separate servers), encrypts files appending ".locked" and drops a ransom note (HOW TO DECRYPT.txt), and deletes the payload after execution to hinder response; Trend Micro attributes the activity to a Mallox affiliate and recommends MFA, robust backups (3-2-1), and regular patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.