Mallox, also known as TargetCompany, Fargo, Tohnichi, Xollam, and later Weaxor, is a financially motivated ransomware operation active since mid-2021. The group is known for repeatedly rebranding its malware while maintaining continuity in tradecraft, victimology, and encryption design. It has operated as a double-extortion actor and has shown signs of evolving toward, and later operating as, a ransomware-as-a-service model. A Linux variant targeting VMware ESXi environments has also been observed, indicating expansion beyond Windows-only operations. Early activity was associated with the Tohnichi name in 2021, followed by Mallox and Fargo in 2022, Xollam in 2023, and Weaxor as a later rebrand. The operation initially focused on compromising vulnerable or weakly secured Microsoft SQL Server environments, including exposed enterprise database servers, and later diversified initial access to spam campaigns using malicious Microsoft OneNote attachments. Reported SQL Server abuse included use of built-in features such as xp_cmdshell and OLE Automation Procedures, with alternative execution paths through SQL Agent jobs, CLR assemblies, or SQL injection also noted. Mallox and related variants have used PowerShell-heavy intrusion chains, reflective loading, in-memory payload execution, and staged delivery to reduce on-disk visibility. Observed tooling and behaviors include AMSI bypass, dynamic API resolution, process injection, use of Cobalt Strike Beacon, and masquerading through trusted Microsoft SQL Server components. The group has also deployed utilities to terminate or uninstall security products, kill processes and services, and otherwise impair endpoint defenses. System information theft and data exfiltration have been part of operations alongside file encryption. The ransomware uses ChaCha20-based encryption, with reporting also noting use of Curve25519 and AES-128 in key generation or key protection workflows in earlier variants. Later reporting on Weaxor describes a custom ChaCha20 implementation and log-clearing behavior to hinder forensic reconstruction. The group has paired encryption with public shaming and data-leak pressure, using a leak site and social-media channels to advertise victims and publish stolen information. Victim targeting has included organizations in India, and the operation has been associated with attacks against multiple enterprises and database-centric environments. Sector evidence supports targeting of financial data and business organizations, and the ESXi-focused Linux variant demonstrates interest in virtualized enterprise infrastructure. One reported affiliate-linked Linux campaign included privilege escalation and exfiltration prior to encryption. Mallox is best understood as the most widely recognized name for this ransomware cluster, with TargetCompany serving as a family designation derived from its victim-specific naming convention and Weaxor representing a later successor or rebrand.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operator behind Weaxor, a rebrand/successor of Mallox, targeting enterprise database servers—especially exposed or weakly secured Microsoft SQL Server deployments—for ransomware execution and file encryption.
TargetCompany is known for conducting ransomware attacks.
TargetCompany is a ransomware group that has evolved to target Linux systems and VMware ESXi environments, using custom scripts for privilege escalation, payload delivery, and data exfiltration. Historically focused on database attacks in East Asia, they have expanded their operations.
A ransomware group operating multiple variants over time, shifting from exploiting vulnerable MS SQL servers for initial access to spam/phishing-style delivery via malicious OneNote attachments, while conducting double extortion and expanding toward a RaaS affiliate model.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.