HomeSecurityNew Linux variant of Mallox ransomware is based on Kryptina code

New Linux variant of Mallox ransomware based on Kryptina code

A subsidiary of the Mallox ransomware operation, also known as TargetCompany, is using a slightly modified version of the Kryptina ransomware to attack Linux systems.

See also: RansomHub introduces EDRKillShifter detection evasion tool

Mallox ransomware Crypto

This version, according to SentinelLabs, is distinct from other Mallox variants targeting Linux, such as the one described last June by researchers at Trend Micro, highlighting the changing tactics of the ransomware ecosystem.

This is also another sign that Mallox ransomware, which previously only targeted Windows , is now targeting Linux and VMWare ESXi systems , marking a significant development for the operation .

Kryptina was released as a low-cost ($500-$800) ransomware-as-a-service (RaaS) for targeting Linux systems in late 2023, but it failed to win over the cybercrime community.

In February 2024, its alleged administrator, using the alias “Corlys”, leaked Kryptina’s source code for free on a hacking forum, apparently obtained by hackers interested in getting their hands on a working Linux variant.

After a Mallox subsidiary suffered an operational error and exposed its tools, SentinelLabs discovered that Kryptina had been adopted and its source code was used to create payloads renamed Mallox.

See also: Vanilla Tempest hackers target healthcare organizations with INC ransomware

The revamped cryptographer, called “Mallox Linux 1.0“, uses the Kryptina kernel source code, the same AES-256-CBC and decryption routines, as well as the same command-line build and configuration parameters.

New Linux variant of Mallox ransomware based on Kryptina code

This indicates that the Mallox subsidiary only modified the appearance and name, removed references to Kryptina from ransom notes, scripts, and files, and ported the existing documentation to a “lite” format, leaving everything else unchanged.

In addition to Mallox Linux 1.0, SentinelLabs found several other tools on the threat actor's server , including:

  • A legitimate Kaspersky password reset tool (KLAPR.BAT)
  • An exploit for CVE-2024-21338, a privilege escalation flaw in Windows 10 and 11
  • Privilege escalation PowerShell scripts
  • Java-based Mallox payload droppers
  • Disk image files containing Mallox payloads
  • Data files for 14 possible victims

Currently, it remains uncertain whether the Mallox Linux 1.0 variant is used by a single affiliate, multiple affiliates, or all Mallox ransomware operators along with the Linux variant discussed in the previous report.

See also: Ransomware gangs abuse Azure Storage Explorer

Ransomware attacks have become a major threat in the digital age, targeting individuals and organizations, encrypting their data and demanding a ransom for its release. These cyberattacks typically exploit vulnerabilities in systems, often delivered via malicious emails or compromised websites. Once ransomware is deployed, victims are presented with an ultimatum to pay the ransom within a specific time frame or face permanent data loss. Despite the potential for data recovery upon payment, there is no guarantee, and paying the ransom can encourage further criminal activity. To combat ransomware, it is important for individuals and businesses to implement strong security measures, including regular data backups, up-to-date antivirus software , and comprehensive cybersecurity training.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS