216.73.217.22

Mallox Ransomware: Linux Variant Decryptor Found

· Published 04/07/2024 10:36 · Modified 04/07/2024 10:53

Export JSON

Essential information

Published
04/07/2024 10:36
Modified
04/07/2024 10:53
Tags
2024-07-04 cyber-extortion encryption fargo mallox mawahelper ransomware targetcompany
Related entities
5 observables, 1 intrusion sets (apt), 19 techniques (mitre), 1 malware

Description

The report analyzes the , which has been active since mid-2021 and focuses on multi-extortion by encrypting victims' data and threatening to post it on public TOR sites. Initially targeting Windows systems, has now developed Linux variants using custom Python scripts for payload delivery and data exfiltration. The analysis reveals a Flask-based web panel for creating Linux builds, with capabilities like user authentication, build management, and admin functions. The encryptor uses AES-256-CBC with a specific key and IV, appends the .lmallox extension to encrypted files, and drops a ransom note. The report also includes decryptors for various build IDs and covers Uptycs XDR detection capabilities and indicators of compromise.

External references