The Mallox Ransomware allows victims to recover files without paying a ransom.

The Mallox ransomware ransom payment process has evolved since its initial appearance, formerly known as TargetCompany. Despite exploiting a cryptographic weakness in February 2022, the malicious actors created new vulnerabilities that allow file recovery without the use of the ECDH private key.
Read more: New Linux variant of Mallox ransomware is based on Kryptina code
These vulnerabilities affected versions of the malware throughout 2023 and early 2024, until the attackers patched them in March 2024.
Avast researchers have identified a critical flaw in Mallox’s cryptographic scheme that allows victims to decrypt their files without paying a ransom. To determine if they have been affected, users can look for files with specific extensions, such as .bitenc, .ma1x0, .mallab, .malox, .mallox, and .xollam. The vulnerable version typically leaves ransom notes in folders with names like “FILE RECOVERY.txt.”
Avast has released a free decryption tool that requires execution on the infected computer, administrative privileges, and the creation of backups of the encrypted files.

See also: Texas UMC health center hit by Ransomware attack
This discovery is particularly significant as the Mallox ransomware group was targeting organizations worldwide, maintaining a presence on social media and the Dark Web until June 2024. Without paying the ransom, organizations risked complete data. Experts warn of the need to strengthen cybersecurity measures and regular backups.
Source: cybersecuritynews
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
