Exfiltration
- Dropmefiles
- File[.]io
- Sendspace
Mallox, also widely tracked as TargetCompany and in some variants as Fargo or Xollam, is an enterprise-focused ransomware family that emerged in 2021 and later operated as a ransomware-as-a-service platform.
Profile source: Mallory opens in a new tabMallox
Mallox, also widely tracked as TargetCompany and in some variants as Fargo or Xollam, is an enterprise-focused ransomware family that emerged in 2021 and later operated as a ransomware-as-a-service platform. It is strongly associated with intrusions against exposed or weakly secured Microsoft SQL Server environments, where operators and affiliates have used brute-force attacks, weak credentials, and exploitation of unpatched SQL Server flaws to gain initial access. Multiple investigations also show abuse of SQL Server features such as xp_cmdshell, OLE automation, and CLR assemblies to execute operating-system commands and stage payloads. Some campaigns used loaders such as PureCrypter or custom .NET downloaders to decrypt and launch Mallox in memory, while later variants and related branches shifted in part to spam-delivered lures, including malicious OneNote attachments.
Reported operators
It was targeted by an intrusion set leveraging brute-force tactics, aiming to deploy the Mallox ransomware via PureCrypter through several MS-SQL exploitation techniques.
Weaxor est le successeur de Mallox ransomware, rebrandé fin 2024 pour contourner les profils de détection.
Mallox ( aka TargetCompany ) ransomware is a longstanding, Enterprise-focused, RaaS. The family emerged in 2021 and is sometimes referred to as FARGO, XOLLAM, or BOZON, due to the extension appended to encrypted files in some variants.
Exploited software
MITRE ATT&CK
Reporting
Attackers targeted externally exposed, unpatched Microsoft SQL Server systems by exploiting CVE-2019-1068 and CVE-2020-0618, then delivered a mix of malware and ransomware through shared infrastructure and tooling. Sophos linked the intrusions through common ingress methods, command-and-control servers, PowerShell downloaders, a .NET downloader, Remcos RAT, the Kill$ cleaner, and 7zip SFX-based loaders, with ransomware payloads including TargetCompany/Mallox and GlobeImposter/Alpha865qqz. Most victims were observed in Asia, with additional cases in the Americas, and Chinese-language comments in some tools suggested the operators may be based in Asia. In one investigated case, the attackers returned after an earlier ransomware incident because the SQL Server remained unpatched, showing how exposed systems can be repeatedly compromised until the root weakness is fixed. Sophos said its defenses blocked follow-on payload delivery and prevented lateral movement, data exfiltration, and further ransom escalation, while responders also identified IOBit Unlocker as an attempted anti-security utility. Continued traffic to a fake KMSAuto-themed download site helped tie the customer incident to the wider campaign.
North Korea-aligned Andariel, a subgroup linked to Lazarus, conducted multiple intrusion campaigns against South Korean organizations across manufacturing, construction, education, defense, telecommunications, semiconductor, shipbuilding, electronics, and ICT sectors. Reporting from AhnLab ties the activity together through recurring victimology, repeated abuse of vulnerable or trusted enterprise software such as INNORIX Agent, domestic asset-management tools, software update mechanisms, and in one case an outdated Apache Tomcat web server. The campaigns also showed likely spearphishing, use of hidden accounts and scheduled tasks for persistence, and credential theft followed by lateral movement and remote desktop access. The operators deployed an evolving malware set that included Goat RAT, AndarLoader, DurianBeacon, Nestdoor, Dora RAT, SmallTiger, TigerRat, NukeSped variants, Black RAT, Lilith RAT, and supporting tools such as PrintSpoofer, Mimikatz, ProcDump, Meterpreter, proxy utilities, keyloggers, clipboard stealers, and browser credential theft tools. AhnLab reported overlaps in command-and-control infrastructure and malware staging, including DurianBeacon delivering AndarLoader, SmallTiger fetching payloads in memory, and some Dora RAT samples being disguised as legitimate software like OpenVPN and signed with valid certificates. The activity reflects a continued shift in Andariel tooling while preserving long-standing tradecraft associated with Lazarus operations.
Attackers have been targeting Oracle WebLogic servers with a newly identified Linux malware dubbed Hadooken, using compromised access to install a cryptominer and the Tsunami DDoS botnet. Researchers observed the activity on a honeypot and found the initial intrusion relied on weak credentials rather than exploitation of a software flaw, after which the operators used shell and Python-based tooling to deploy malware, gain persistence through cron jobs, and erase logs to reduce visibility. Post-compromise activity showed the attackers searching for SSH data, attempting lateral movement, and expanding control across Linux environments. Analysis also linked Hadooken infrastructure and code overlaps to RHOMBUS and NoEscape ransomware families, while a PowerShell payload hosted on a related delivery server was seen downloading Mallox ransomware for Windows, indicating the campaign may combine immediate monetization through cryptomining and DDoS with follow-on ransomware operations against mixed Linux and Windows estates.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.