TargetCompany is a financially motivated ransomware operation active since June 2021, associated with the Mallox, Fargo, Tohnichi, and Xollam names. Weaxor is its successor branding, introduced in late 2024. The operation targets enterprise database servers, particularly vulnerable, misconfigured, or internet-exposed Microsoft SQL Server deployments, and has expanded to Linux systems running VMware ESXi. Its victims include small businesses and organizations in manufacturing, information technology, retail, telecommunications, apparel, and automotive industries. Documented targeting includes India, Saudi Arabia, and the Netherlands. Initial-access techniques include exploitation of Microsoft SQL Server environments and spam campaigns delivering malicious Microsoft OneNote attachments. Intrusions abuse SQL Server execution features, including xp_cmdshell and OLE Automation Procedures, and use obfuscated PowerShell loaders, reflective loading, and in-memory payload execution. Operators have used Mimikatz for credential theft, network scanning for reconnaissance, and tools that terminate security processes or remove antivirus products. Weaxor campaigns employ Cobalt Strike, process injection, AMSI bypass, masquerading through signed Microsoft software, and Windows event-log clearing. A Linux variant uses a custom shell script for privilege escalation and data exfiltration. TargetCompany conducts double extortion, combining file encryption with theft and threatened publication of victim data. It has operated a public leak site under the Mallox name and used social platforms to publicize victims. Its ransomware uses ChaCha20, with Curve25519 and AES-128 involved in encryption-key handling. The operation has recruited affiliates and operates a ransomware-as-a-service model under Weaxor. An affiliate identified as vampire has been associated with its Linux attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
TargetCompany has been observed to use CVE-2019-1069 and CVE-2020-0618, remote code execution (RCE) vulnerabilities that allow attackers to execute arbitrary code.
TargetCompany has been observed to use CVE-2019-1069 and CVE-2020-0618, remote code execution (RCE) vulnerabilities that allow attackers to execute arbitrary code.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operator behind Weaxor, a rebrand/successor of Mallox, targeting enterprise database servers—especially exposed or weakly secured Microsoft SQL Server deployments—for ransomware execution and file encryption.
A financially motivated ransomware group primarily attacking vulnerable database servers, particularly Microsoft SQL Servers. It encrypts files and publishes victims that refuse payment on its leak site. The report describes a small, closed group, affiliate recruitment for a Mallox ransomware-as-a-service program, and possible operational connections with BruteSQL. Many identified victims were small businesses.
TargetCompany is known for conducting ransomware attacks.
TargetCompany is a ransomware group that has evolved to target Linux systems and VMware ESXi environments, using custom scripts for privilege escalation, payload delivery, and data exfiltration. Historically focused on database attacks in East Asia, they have expanded their operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.