Mallox is a financially motivated, enterprise-focused ransomware operation active since June 2021, also known as TargetCompany, FARGO, XOLLAM, BOZON, and Mawahelper. Initially operating privately, it introduced an affiliate program in 2022 and adopted double extortion, combining file encryption with threats to publish stolen information on a data-leak site. Its recruitment targeted experienced Russian-speaking affiliates and organizations with annual revenue exceeding $10 million. Principal target countries include the United States, United Kingdom, Canada, Australia, and Germany. Its geographic origin is not established. Mallox operators frequently obtain initial access through internet-exposed Microsoft SQL Server instances, using brute-force attacks against weak credentials and exploiting unsecured or vulnerable servers. Observed intrusion techniques include SQL CLR assembly abuse, xp_cmdshell and OLE automation for operating-system command execution, and PowerShell-based payload delivery. Enterprise compromises have involved AnyDesk for persistent remote access, Mimikatz for credential theft, SoftPerfect NetScan for network discovery, attacker-created accounts for lateral movement, and FileZilla for data exfiltration. Payload delivery has included PureCrypter and other .NET loaders that decrypt and load ransomware in memory. Before encryption, Mallox can stop applications and services, delete shadow copies, disable recovery mechanisms, and transmit victim-system information to its infrastructure. Variants check system language or location to avoid execution in Russian-speaking environments. The affiliate ecosystem includes operators identified as Maestro, Hiervos, and Vampire, alongside identifiers such as admin and panda. Observed affiliate behavior ranges from opportunistic encryption of individual servers to broader corporate compromises with substantially larger ransom demands and double-extortion pressure. Mallox supports Windows and Linux attacks. A Linux variant maintained by one affiliate was derived from the open-source Kryptina ransomware platform and retained its AES-256-CBC encryption implementation; that lineage does not apply to all Mallox Linux variants.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operation distributing Mallox ransomware, primarily gaining access via vulnerable MS-SQL servers, brute-force and weak credentials, and conducting both single-server ransomware deployments and broader double-extortion intrusions.
Associated with a staging server leak that revealed how the Kryptina platform was adapted for enterprise ransomware attacks, including extending operations into Linux and cloud environments.
Ransomware operation that began as a private group and later launched an affiliate program. It restricts participation to Russian-speaking, experienced affiliates and conducts big game hunting against larger organizations while excluding hospitals and educational institutions.
Enterprise-focused ransomware-as-a-service operation whose affiliates used a modified Kryptina-based Linux ransomware variant ('Mallox v1.0') and Windows droppers/tools. The content says Mallox operators opportunistically target timely vulnerabilities such as MSSQL Server and commonly use brute force attacks for initial access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.