Quorum Cyber
Mallox Ransomware Threat Intelligence Report
Pages
8
Time to read
5 mins
Publication
Language
English
Pages
8
Time to read
5 mins
Publication
Language
English
This document is a threat intelligence report focusing on Mallox ransomware, which has been observed targeting various industries across multiple countries, including Japan, India, and the United States. The report outlines the operational methods of Mallox ransomware, particularly its use of a double-extortion technique where stolen data is threatened to be leaked unless a ransom is paid. It details the impact of successful exploitation, which includes the encryption and exfiltration of significant data, leading to potential reputational damage for affected organizations. The document also describes incident detection strategies, emphasizing the importance of endpoint detection and response (EDR) solutions like Microsoft Defender. Additionally, it lists indicators of compromise associated with Mallox ransomware, including specific domains and file hashes. The report concludes with an overview of the threat landscape, noting the increasing frequency of ransomware attacks and the emergence of Mallox as a notable strain within the ransomware ecosystem.