Skip to content

Mallox

Mallox, also widely tracked as TargetCompany and in some variants as Fargo or Xollam, is an enterprise-focused ransomware family that emerged in 2021 and later operated as a ransomware-as-a-service platform.

Profile source: Mallory opens in a new tab

Mallox

Family profile

Mallox, also widely tracked as TargetCompany and in some variants as Fargo or Xollam, is an enterprise-focused ransomware family that emerged in 2021 and later operated as a ransomware-as-a-service platform. It is strongly associated with intrusions against exposed or weakly secured Microsoft SQL Server environments, where operators and affiliates have used brute-force attacks, weak credentials, and exploitation of unpatched SQL Server flaws to gain initial access. Multiple investigations also show abuse of SQL Server features such as xp_cmdshell, OLE automation, and CLR assemblies to execute operating-system commands and stage payloads. Some campaigns used loaders such as PureCrypter or custom .NET downloaders to decrypt and launch Mallox in memory, while later variants and related branches shifted in part to spam-delivered lures, including malicious OneNote attachments.

Capabilities

  • Brute Force
  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence

Operational record

1
YARA rules
2
Ransom notes
3
Negotiations
1
Leak sites
0 available

Exfiltration

  • Dropmefiles
  • File[.]io
  • Sendspace

Reported operators

Threat actors

3 named in public reporting
8220 Gang

It was targeted by an intrusion set leveraging brute-force tactics, aiming to deploy the Mallox ransomware via PureCrypter through several MS-SQL exploitation techniques.

targetcompany

Weaxor est le successeur de Mallox ransomware, rebrandé fin 2024 pour contourner les profils de détection.

Lazarus

Mallox ( aka TargetCompany ) ransomware is a longstanding, Enterprise-focused, RaaS. The family emerged in 2021 and is sometimes referred to as FARGO, XOLLAM, or BOZON, due to the extension appended to encrypted files in some variants.

Exploited software

Vulnerabilities linked to Mallox

4 CVEs

MITRE ATT&CK

Mallox in ATT&CK

32 distinct techniques

Reporting

Research mentioning Mallox

Jan 1
Sophos Threat Research

OODA: X-Ops Takes On Burgeoning SQL Server Attacks | SOPHOS

Attackers targeted externally exposed, unpatched Microsoft SQL Server systems by exploiting CVE-2019-1068 and CVE-2020-0618, then delivered a mix of malware and ransomware through shared infrastructure and tooling. Sophos linked the intrusions through common ingress methods, command-and-control servers, PowerShell downloaders, a .NET downloader, Remcos RAT, the Kill$ cleaner, and 7zip SFX-based loaders, with ransomware payloads including TargetCompany/Mallox and GlobeImposter/Alpha865qqz. Most victims were observed in Asia, with additional cases in the Americas, and Chinese-language comments in some tools suggested the operators may be based in Asia. In one investigated case, the attackers returned after an earlier ransomware incident because the SQL Server remained unpatched, showing how exposed systems can be repeatedly compromised until the root weakness is fixed. Sophos said its defenses blocked follow-on payload delivery and prevented lateral movement, data exfiltration, and further ransom escalation, while responders also identified IOBit Unlocker as an attempted anti-security utility. Continued traffic to a fake KMSAuto-themed download site helped tie the customer incident to the wider campaign.

Jan 22
Ahnlab Asec

RID Hijacking Technique Utilized by Andariel Attack Group - ASEC

North Korea-aligned Andariel, a subgroup linked to Lazarus, conducted multiple intrusion campaigns against South Korean organizations across manufacturing, construction, education, defense, telecommunications, semiconductor, shipbuilding, electronics, and ICT sectors. Reporting from AhnLab ties the activity together through recurring victimology, repeated abuse of vulnerable or trusted enterprise software such as INNORIX Agent, domestic asset-management tools, software update mechanisms, and in one case an outdated Apache Tomcat web server. The campaigns also showed likely spearphishing, use of hidden accounts and scheduled tasks for persistence, and credential theft followed by lateral movement and remote desktop access. The operators deployed an evolving malware set that included Goat RAT, AndarLoader, DurianBeacon, Nestdoor, Dora RAT, SmallTiger, TigerRat, NukeSped variants, Black RAT, Lilith RAT, and supporting tools such as PrintSpoofer, Mimikatz, ProcDump, Meterpreter, proxy utilities, keyloggers, clipboard stealers, and browser credential theft tools. AhnLab reported overlaps in command-and-control infrastructure and malware staging, including DurianBeacon delivering AndarLoader, SmallTiger fetching payloads in memory, and some Dora RAT samples being disguised as legitimate software like OpenVPN and signed with valid certificates. The activity reflects a continued shift in Andariel tooling while preserving long-standing tradecraft associated with Lazarus operations.

Sep 13
Bleeping Computer

New Linux malware Hadooken targets Oracle WebLogic servers

Attackers have been targeting Oracle WebLogic servers with a newly identified Linux malware dubbed Hadooken, using compromised access to install a cryptominer and the Tsunami DDoS botnet. Researchers observed the activity on a honeypot and found the initial intrusion relied on weak credentials rather than exploitation of a software flaw, after which the operators used shell and Python-based tooling to deploy malware, gain persistence through cron jobs, and erase logs to reduce visibility. Post-compromise activity showed the attackers searching for SSH data, attempting lateral movement, and expanding control across Linux environments. Analysis also linked Hadooken infrastructure and code overlaps to RHOMBUS and NoEscape ransomware families, while a PowerShell payload hosted on a related delivery server was seen downloading Mallox ransomware for Windows, indicating the campaign may combine immediate monetization through cryptomining and DDoS with follow-on ransomware operations against mixed Linux and Windows estates.

Sep 12
Aquasec Other

Hadooken Malware Targets Weblogic Applications

May 27
Ahnlab Asec

국내 기업 대상 공격에 사용 중인 SmallTiger 악성코드 (Kimsuky, Andariel 그룹) - ASEC

May 16
Ahnlab Asec

Dora RAT을 이용한 국내 기업 대상 APT 공격 사례 분석 (Andariel 그룹) - ASEC

Nov 10
Ahnlab Asec

자산 관리 프로그램을 악용한 공격 정황 포착 (Andariel 그룹) - ASEC

Aug 22
Ahnlab Asec

Andariel 그룹의 새로운 공격 활동 분석 - ASEC

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.