logo

Mallox Ransomware showing signs of Increased Activity

ID: ab8ecb4c-883f-56da-9ccc-83afeb3475c1

STIX ID: report--ab8ecb4c-883f-56da-9ccc-83afeb3475c1

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-05-21

Date Updated: 2026-07-20

...
...

Cyble CRIL reports increased Mallox ransomware activity: an unknown .NET loader (delivered via spam) downloads an AES-encrypted payload (e.g., http://80.66.75.98/Chseiyk.jpeg), decrypts it in memory and loads a .NET DLL that performs service termination (including GPS-related services), system information exfiltration, and file encryption appending ".Mallox". The report includes technical analysis of the loader and payload (filenames and SHA256 hashes), a list of stopped services (databases, backups, virtualization, GPS services), the ransom note and victim chat/leak site, IoCs (hashes and URLs), and recommended defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.