This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company> Known victims: 49 3 negotiation log(s) available, 2 ransom note(s) on file
Objectives
Executive Summary
The mallox threat actor is a medium-sophistication criminal group primarily involved in ransomware activities, targeting organizations for financial gain. Known since November 2022, this actor has demonstrated the ability to compromise victim systems through a combination of advanced cryptographic methods and targeted campaigns.
Goals & Targeting
Millox's primary objectives are financial gain through ransom payments and organizational disruption. They typically target mid-sized businesses across various sectors, focusing on regions where ransom支付 demands are feasible without attracting excessive law enforcement attention.
Enhanced Description
Millox is a ransomware operator characterized by their use of multiple encryption algorithms, including ChaCha20, AES-128, and Curve25519. The group's activity has been tracked from mid-2021, with their first confirmed operations beginning in 2022. Mallox targets businesses across various sectors, encrypting files and appending extensions related to the compromised company. Their operational timeline extends through July 2024, indicating sustained ransomware distribution efforts. The group has demonstrated a focus on negotiation tactics, leveraging victims' need for data recovery to extract ransoms. Known victims number 49, with associated phishing campaigns and encrypted file patterns.
Key Capabilities
Software / Tooling
Campaigns & Victims
Millox has been active since mid-2021, with confirmed operations from November 2022 to July 2024. Their campaigns typically involve targeted phishing attempts, encrypted file exfiltration, and structured negotiations. Notable patterns include the use of .<target_company> file extensions for encrypted files and potential DDoS threats if ransoms are not paid.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence due to limited linked intelligence and TTP details. Data gaps include exact targeting sectors, associated campaigns, and MITRE mappings.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics