Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors mallox

Description

This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .<target_company> Known victims: 49 3 negotiation log(s) available, 2 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The mallox threat actor is a medium-sophistication criminal group primarily involved in ransomware activities, targeting organizations for financial gain. Known since November 2022, this actor has demonstrated the ability to compromise victim systems through a combination of advanced cryptographic methods and targeted campaigns.

Goals & Targeting

Millox's primary objectives are financial gain through ransom payments and organizational disruption. They typically target mid-sized businesses across various sectors, focusing on regions where ransom支付 demands are feasible without attracting excessive law enforcement attention.

Enhanced Description

Millox is a ransomware operator characterized by their use of multiple encryption algorithms, including ChaCha20, AES-128, and Curve25519. The group's activity has been tracked from mid-2021, with their first confirmed operations beginning in 2022. Mallox targets businesses across various sectors, encrypting files and appending extensions related to the compromised company. Their operational timeline extends through July 2024, indicating sustained ransomware distribution efforts. The group has demonstrated a focus on negotiation tactics, leveraging victims' need for data recovery to extract ransoms. Known victims number 49, with associated phishing campaigns and encrypted file patterns.

Key Capabilities

  • Ransomware deployment
  • Advanced encryption techniques
  • Spear-phishing campaigns
  • Negotiation tactics
  • Data exfiltration

Software / Tooling

RansomToolXOR

Campaigns & Victims

Millox has been active since mid-2021, with confirmed operations from November 2022 to July 2024. Their campaigns typically involve targeted phishing attempts, encrypted file exfiltration, and structured negotiations. Notable patterns include the use of .<target_company> file extensions for encrypted files and potential DDoS threats if ransoms are not paid.

IOC Patterns

  • Phishing emails with malicious attachments
  • Encrypted files with company-specific extensions
  • Network traffic anomalies during encryption

Recommended Actions

  • Implement strict phishing email filters
  • Segment networks to limit lateral movement
  • Monitor for encrypted file patterns
  • Establish incident response plans for ransomware events

Suggested Tags

APT
ransomware
financial-gain
mid-sized business targeting

Confidence Assessment

Low confidence due to limited linked intelligence and TTP details. Data gaps include exact targeting sectors, associated campaigns, and MITRE mappings.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
financial-gain
mid-sized business targeting

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Nov 4, 2022
Last Seen
Jul 14, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.