From Private Malware To Raas : The Rise Of Mallox

6 Days(s) Ago    👁 68
from private malware to raas the rise of mallox

The recent rapid proliferation and increased sophistication of Mallox ransomware signals pressing demand for organisations to urgently bolster their defences protecting digital assets and mitigating risks. To address this need, Kaspersky has released the Mallox ransomware: In-depth analysis and evolution report . The new publication provides a comprehensive analysis of Mallox ransomware, chronicling its transformation from privately operated malware to full-scale RaaS operation.

The report highlights Malloxs significant impact since its initial appearance in early 2021. Originally highly targeted, human-operated ransomware, Mallox inflicted severe damage on organisations worldwide. Kasperskys research details how this previously isolated threat has rapidly evolved with more than 700 new samples identified from 2021 to mid-2024. This surge in activity is largely attributed to Malloxs transition into a RaaS model, enabling it to expand aggressively by recruiting affiliates and partners through a dark web forum.

In January 2023, the operators behind Mallox launched a robust RaaS affiliate programme, actively seeking skilled pen testers to expand their reach. Offering lucrative profit-sharing terms, the programme has attracted a host of cybercriminals, contributing to a marked increase in Mallox-related attacks. The report delves into advancements in Malloxs encryption schemes, which have become increasingly sophisticated. Kasperskys detailed analysis of these cryptographic techniques underscores continuous innovation by Mallox developers to enhance the ransomwares efficacy.

The report also sheds light on Malloxs global spread, focusing on its preferred infection vectors. Notably, the attackers often exploit vulnerabilities in MS SQL and PostgreSQL servers, demonstrating its adaptability and threat to a broad range of industries. This in-depth analysis serves as an essential resource for cybersecurity professionals, offering critical insights into the nature and evolution of this formidable ransomware. Mallox has demonstrated a particular preference for targeting certain regions. Brazil, Vietnam and China have emerged as the most frequently targeted countries. Although India, Russia, Saudi Arabia, Lebanon, Colombia, Turkiye and the United States of America have experienced fewer attacks, they remain vulnerable to the ransomwares threat.

Understanding the Mallox ransomware its evolution, characteristics and devastating potential empowers organisations to fortify their defences. With the right security measures in place, companies can protect their digital assets and diminish the risk of becoming the next target of this formidable threat, comments Kaspersky security expert Fedor Sinitsyn.