{"id":3921,"date":"2024-06-06T12:33:22","date_gmt":"2024-06-06T17:33:22","guid":{"rendered":"https:\/\/www.darkreading.com\/cloud-security\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environment"},"modified":"2024-06-06T12:33:22","modified_gmt":"2024-06-06T17:33:22","slug":"mallox-ransomware-variant-targets-privileged-vmware-esxi-environments","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/06\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments\/","title":{"rendered":"Mallox Ransomware Variant Targets Privileged VMWare ESXi Environments"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltf7008c1b9e8db134\/654e3a06e66755040a2171f8\/Ransomware_marcos_alvarado_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/mallox-ransomware-group-revamps-malware-variants-evasion-tactics\" rel=\"noopener\">The Mallox ransomware group<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is targeting VMWare ESXi environments with a fresh Linux variant that employs a new technique, to deliver and execute its payload only in machines with high-level user privileges.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The variant \u2014 discovered by researchers at Trend Micro who track Mallox as TargetCompany \u2014 specifically determines if a targeted system is running in a VMWare ESXi environment and has administrative rights, and won&#8217;t proceed with an attack if these requirements are not met, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/f\/targetcompany-s-linux-variant-targets-esxi-environments.html\" rel=\"noopener\">according to a blog post<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> published June 5.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mallox, which is also known by the monikers Fargo and Tohnichi, first surfaced in June 2021 and claims to have <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/nigerian-businesses-face-growing-ransomware-as-a-service-trade\" rel=\"noopener\">infected hundreds of organizations<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> worldwide. Specific sectors targeted by the group include manufacturing, retail, wholesale, legal, and professional services. This year Mallox has been most active in Taiwan, India, Thailand, and South Korea, according to Trend Micro.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Custom Shell Shows Sophistication\">Custom Shell Shows Sophistication<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Linux variant is the first time <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/mallox-ransomware-group-revamps-malware-variants-evasion-tactics\" rel=\"noopener\">Mallox has been seen using a custom shell script<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to deliver and execute ransomware on virtualized environments \u2014 activity likely aimed at creating more disruption and, thus, increasing chances of a ransom payout.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Moreover, the adversary responsible for wielding the variant is a Mallox affiliate called \u201cvampire,\u201d which indicates the group&#8217;s involvement in &#8220;broader campaigns involving high ransom demands and expansive IT system targeting,&#8221; Trend Micro&#8217;s Darrel Tristan Virtusio, Nathaniel Morales, and Cj Arsley Mateo wrote in the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The use of a custom shell also demonstrates that Mallox &#8220;has been continuously evolving to employ more sophisticated methods in its future attacks,&#8221; the researchers noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This recently found Linux variant <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/akira-ransomware-mutates-to-target-linux-systems-adds-ttps\" rel=\"noopener\">aligns with the recent trend<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/key-group-ransomware-decryptor\" rel=\"noopener\">ransomware groups extending their attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to critical Linux environments, thereby potentially increasing the range of target victims,&#8221; they observed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In addition to delivery and execution, the custom shell also exfiltrates the victim&#8217;s information to two different servers so the ransomware actors have a backup of the information. Mallox is known to use a leak site by the same name to expose data stolen from its ransomware attacks.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"How the Mallox Variant Works\">How the Mallox Variant Works<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This latest variant first checks a system to see whether the executable is running with administrative rights and, if this is not the case, it won&#8217;t continue its activity.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After execution, the variant drops a text file named <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">TargetInfo.txt <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">that contains victim information that is sent to a command-and-control (C2) server, behavior that is similar to the Windows version of Mallox ransomware.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The IP address used to exfiltrate this info as well as later execute the payload is one not seen used by Mallox before, the researchers noted. It&#8217;s hosted by China Mobile Communications, a Chinese ISP, and was likely rented for short-term use by the threat actor to host its malicious payload, they said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The binary also performs a check to determine whether the machine is running in a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/agenda-ransomware-vmware-esxi-servers\" rel=\"noopener\">VMWare ESXi environment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by seeing if the system name matches \u201cvmkernel,&#8221; which indicates that the machine is running in VMware\u2019s ESXi hypervisor. If so, it deploys its encryption routine, appending the extension &#8220;.locked&#8221; on encrypted files and dropping a ransom note named <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">HOW TO DECRYPT.txt<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Both the extension and note deviate from the Windows variant, the researchers noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The custom shell script used to download and execute the payload also can exfiltrate data to a different server. It does this by reading the contents of the dropped text file and uploading it to another URL once the ransomware performs its routine. The variant also notably exfiltrates victim information to two different servers, possibly &#8220;to &nbsp;improve redundancy and have a backup in case a server goes offline or is compromised,&#8221; the researchers wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">After the ransomware performs its routine, the script deletes the TargetCompany payload, creating an added challenge for defenders to understand the overall impact of the attack, thus making investigation and incident response difficult.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Linux ESXi Environments Beware of Cyberattacks\">Linux ESXi Environments Beware of Cyberattacks<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Mallox&#8217;s sophisticated expansion of its attack activity into Linux environments running VMware ESXi requires renewed vigilance on the part of organizations that fit this description, the researchers noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Implementing tried-and-tested cybersecurity measures can mitigate the risk of falling victim to ransomware attempts and protect the data integrity of an organization&#8217;s assets,&#8221; they wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Best practices that the researchers suggested organizations should take include <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/tycoon-malware-kit-bypasses-microsoft-google-mfa\" rel=\"noopener\">enabling multifactor authentication (MFA)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to prevent attackers from performing lateral movement inside a network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">They also should adhere to what&#8217;s called the &#8220;3-2-1 rule&#8221; for backing up important files; that is, &#8220;creating three backup copies on two different file formats, with one of the copies stored in a separate location,&#8221; the researchers noted. Finally, the researchers said, patching and updating systems regularly can deter malicious actors from exploiting software vulnerabilities.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cloud-security\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environment\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Mallox ransomware group is targeting VMWare ESXi environments with<\/p>\n","protected":false},"author":12,"featured_media":3922,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3921","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?fit=1200%2C861&ssl=1",1200,861,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?fit=300%2C215&ssl=1",300,215,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?fit=640%2C459&ssl=1",640,459,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?fit=640%2C459&ssl=1",640,459,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?fit=1200%2C861&ssl=1",1200,861,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?fit=1200%2C861&ssl=1",1200,861,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?fit=1024%2C735&ssl=1",1024,735,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/06\/mallox-ransomware-variant-targets-privileged-vmware-esxi-environments.jpg?fit=1200%2C861&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3921"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3921\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3922"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}