Technical profile
Mallox
Unit 42 describes Mallox targeting Windows and gaining access through poorly protected MS-SQL.
Confirmed (Confirmed) · Reference profile status, not attribution for an individual case.
- Name / status
- Mallox · Confirmed
- Aliases
- TargetCompany • FARGO • Tohnichi — theo Unit 42.
- First seen
- June 2021 according to Unit 42.
- Target platforms
- Windows; this profile does not extend conclusions to other variants.
- TTP
- The research describes MS-SQL brute force, execution and recovery inhibition.
- Current Activity
- No verified current activity dataset is available in this profile.
- Target sectors
- Sector categories have not been standardized in V1.
- MITRE ATT&CK
- Compare techniques against the reference sources; see the TTP Map.
- IOC
- Use only sourced, contextualized indicators; see IOC Watch.
- Extension
- .malox and variants described in the source; not independent attribution criteria.
- Ransom note
- See the sample note in Unit 42's report; no note from a Vietnamese case is published here.
- Encryption behavior
- The researched sample uses ChaCha20; do not apply this conclusion to every sample.
- Partial / Full / Chunked
- No separate measurements on a representative sample.
- Public decryptor status
- Insufficient data
- Recovery Intelligence
- No validated recovery observations support generalization to all variants.
- Leak site
- Leak-site claims are not independent evidence. Direct links are not published.
- Known incidents
- No separately verified incident list has been added to this profile.
- Detection notes
- Compare multiple evidence sources; distinguish a single indicator from a conclusion about the entire incident.
- Recovery notes
- Assess samples and data structures. A family name alone does not establish recovery prospects.
- Last updated
- 09/10/2026 (UTC+7)
Sources
Palo Alto Networks Unit 42 — Mallox Ransomware2023 · Sample research and intrusion chain analysis by Unit 42.
Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.
Update history
09/10/2026 · Added recovery scope, decryptor status and tool links; marked fields with insufficient data.
04/10/2026 · Created the reference profile and clearly marked missing data.