Researchers detailed an active Weaxor ransomware campaign targeting enterprise Microsoft SQL Server environments, particularly internet-exposed or misconfigured servers with weak administrator credentials. The operation is described as the late-2024 rebrand and successor to the Mallox/TargetCompany ransomware family and is reportedly run as a ransomware-as-a-service platform. In the observed intrusion chain, attackers abused SQL Server features including xp_cmdshell and OLE Automation Procedures to trigger a heavily obfuscated PowerShell loader, which decrypted and downloaded a second-stage payload identified as update.exe.
The second stage deployed a Cobalt Strike Beacon in memory, using techniques such as dynamic API resolution, PEB traversal, ROR13 API hashing, and WinINet communications to retrieve additional payloads from remote infrastructure, including 154.201.236.197, while reducing static detection. The final payload injected into the legitimate signed SQL administration utility SQLPS.exe, launched ransomware from a randomized path under C:\Windows\System32, encrypted files with a custom ChaCha20 implementation, appended the .weax extension, and cleared Windows event logs through wevtapi.dll, hindering forensic reconstruction and attribution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2024-04-15, Sekoia observed an attacker brute-force the sa account on an exposed MS-SQL honeypot and later attempt to deploy Mallox ransomware. The intrusion used recurring MS-SQL exploitation patterns and dropped PureCrypter, which decrypted and reflectively loaded a DLL that ultimately executed Mallox.
By late 2024, the operators renamed their payload from Mallox to Weaxor while continuing to target enterprise Microsoft SQL Server environments. The rebrand is described as an evolution of the same operation.
The threat group later associated with Mallox and Weaxor first appeared in mid-2021 under labels such as TargetCompany. The references describe this as the start of the operation's activity.
K7 Computing Labs published a reverse-engineering and forensic analysis of an active Weaxor ransomware campaign. The report detailed SQL Server abuse, PowerShell staging, Cobalt Strike Beacon use, and final ransomware execution via SQLPS.exe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyberveille.ch
Open sourceblog.sekoia.io
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.