logo

Mallox Ransomware Implements New Infection Strategy

ID: 17304a49-a21c-5d28-8d92-b68531c51049

STIX ID: report--17304a49-a21c-5d28-8d92-b68531c51049

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-18

Date Updated: 2026-07-16

...
...

This report analyzes a Mallox (also spelled Mallox/Malox) ransomware campaign that uses BatLoader delivered via spam attachments to execute a fileless payload: an obfuscated batch/PowerShell chain that reconstructs and loads a ransomware assembly in-memory and injects it into MSBuild.exe, encrypting files with a ".malox" extension. The report describes the technical infection chain, persistence and destructive actions (mass task/service termination and deletions), geographic and industry victim distribution, MITRE ATT&CK mappings, and provides hashes, malicious URLs, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.