Mallox is a ransomware group targeting individual companies, altering file extensions to the victim's name.
Analyst brief
Mallox is a ransomware group targeting individual companies. After encrypting files, they change the file extension to the victim company's name. Their key TTPs involve a combination of multiple cryptographic algorithms, including ChaCha20, AES-128, and Curve25519. Defenders should focus on network segmentation and maintaining offline backups against this threat that has been active since mid-2021.
mallox
crime
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company>