Threat Advisory

Mallox Group Claims Ransomware Attack on FICCI

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers discovered that Mallox Ransomware Group claimed to have compromised networks of the Federation of Indian Chambers of Commerce & Industry (FICCI) on February 23, 2023. Mallox Ransomware has evolved from the original "TargetCompany" ransomware strain, changing its strategies and methods. The malware has expanded its dissemination. In addition to using the same username in their email addresses as shown in the ransom letters, the organization had also been encrypting files with the extension ".mallox.". However, they suddenly branded themselves as "Mallox" on their leak site. One of the top organizations in India, The unidentified loader, which typically shows up in spam emails and tempts the targeted account to open the files, is how Mallox ransomware gets delivered. It is known that the loader downloads various malware families, including keyloggers like Agentesla, Remcos, and Snake. The organization provides a "PrivateSignin" ".onion" URL to communicate them in their ransom note. This URL requests a private key that is specific to one company. When entered, the private key takes the user to a Tor webpage that displays the target ID, the ransom amount, and an area to test the decrypted files.[/subscribe_to_unlock_form]

Summary:

Researchers discovered that Mallox Ransomware Group claimed to have compromised networks of the Federation of Indian Chambers of Commerce & Industry (FICCI) on February 23, 2023. Mallox Ransomware has evolved from the original "TargetCompany" ransomware strain, changing its strategies and methods. The malware has expanded its dissemination. In addition to using the same username in their email addresses as shown in the ransom letters, the organization had also been encrypting files with the extension ".mallox.". However, they suddenly branded themselves as "Mallox" on their leak site. One of the top organizations in India, The unidentified loader, which typically shows up in spam emails and tempts the targeted account to open the files, is how Mallox ransomware gets delivered. It is known that the loader downloads various malware families, including keyloggers like Agentesla, Remcos, and Snake. The organization provides a "PrivateSignin" ".onion" URL to communicate them in their ransom note. This URL requests a private key that is specific to one company. When entered, the private key takes the user to a Tor webpage that displays the target ID, the ransom amount, and an area to test the decrypted files.[emaillocker id="1283"]

 

Threat Profile:

References:

The following reports contain further technical details:

https://blog.cyble.com/2023/02/24/mallox-group-claims-ransomware-attack-on-ficci/

[/emaillocker]
crossmenu