Cyber Security

Mallox Ransomware Flaw Let Victims Recover Files Without Ransom Payment

Mallox Ransomware Flaw Lets Victims Recover Files Without Ransom Payment. Previously known as TargetCompany, ransomware has undergone several evolutionary changes since its initial appearance.

While the malicious actors addressed an earlier cryptographic weakness in February 2022, their subsequent modifications introduced new vulnerabilities that now allow for file recovery without requiring the private ECDH key.

The vulnerability affected versions of the active malware throughout 2023 and early 2024, though the attackers patched it in March 2024.

Avast researchers have uncovered a critical flaw in the Mallox ransomware’s cryptographic schema, enabling victims to recover their encrypted files without paying ransom demands.

National Cybersecurity Awareness Month Cyber Challenges – Test your Skills Now

Identifying Affected Systems

Victims can identify if they’ve been affected by the decryptable version by looking for files with specific extensions, including .bitenc, .ma1x0, .mallab, .malox, .mallox, and .xollam.

The vulnerable version of the malware typically leaves ransom notes in each affected folder with names such as “FILE RECOVERY.txt” or “HOW TO RESTORE FILES.txt”.

Avast has released a free decryption tool that can restore affected files. The recovery process requires:

  • Running the decryptor on the originally infected computer
  • Administrative privileges for the decryption process
  • Backing up encrypted files before attempting recovery
Decrypter

The discovery represents a significant setback for the Mallox operation, which has been actively targeting organizations worldwide.

The ransomware group maintained a presence on social media platforms and operated a Dark Web leak site, documenting victims through June 2024.

Without paying the ransom, affected organizations faced the risk of complete data loss or potential exposure of stolen information.

Security experts emphasize the importance of maintaining vigilance against ransomware attacks, as threat actors continuously modify their tactics.

Organizations should monitor for suspicious system behavior, such as unusual processing loads or memory usage, which could indicate an ongoing attack.

The availability of this decryption solution offers hope to victims while highlighting the importance of robust cybersecurity measures and regular system backups.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Watch Here

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago