Mallox Ransomware showing signs of Increased Activity
ID: ab8ecb4c-883f-56da-9ccc-83afeb3475c1
STIX ID: report--ab8ecb4c-883f-56da-9ccc-83afeb3475c1
Feed Name: Cyble Blog
Cyble CRIL reports increased Mallox ransomware activity: an unknown .NET loader (delivered via spam) downloads an AES-encrypted payload (e.g., http://80.66.75.98/Chseiyk.jpeg), decrypts it in memory and loads a .NET DLL that performs service termination (including GPS-related services), system information exfiltration, and file encryption appending ".Mallox". The report includes technical analysis of the loader and payload (filenames and SHA256 hashes), a list of stopped services (databases, backups, virtualization, GPS services), the ransom note and victim chat/leak site, IoCs (hashes and URLs), and recommended defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
