Friday, April 4, 2025
HomeCyber Security NewsNew Mallox Ransomware Linux Variant Attacking Enterprise Linux Servers

New Mallox Ransomware Linux Variant Attacking Enterprise Linux Servers

Published on

SIEM as a Service

Follow Us on Google News

Kryptina RaaS, a free and open-source RaaS platform for Linux, initially struggled to attract attention.

Still, after a Mallox affiliate’s staging server was leaked in May 2024, Kryptina’s modified version, branded Mallox v1.0, gained prominence. 

The research examines the data exposed in the leak, highlighting differences between the original Kryptina RaaS (v2.2) and Mallox v1.0 by revealing that the Mallox variant incorporates enhancements to the platform’s functionality, making it a more attractive option for threat actors seeking to launch ransomware campaigns.

First discovery of an open directory on the Mallox affiliate server
First discovery of an open directory on the Mallox affiliate server

Mallox, a mature ransomware-as-a-service platform, has been active since 2021, targeting enterprises through vulnerabilities and brute force attacks. Kryptina, initially sold by “Corlys,” was later leaked online, revealing its source code and connection to Mallox. 

This leak exposed a Mallox affiliate’s use of Kryptina for Linux payloads, suggesting a potential collaboration or customization.

However, Kryptina’s uniqueness within the Mallox ecosystem indicates a complex relationship between the two, possibly involving independent development or acquisition.

Kryptina database in Mallox leak
Kryptina database in Mallox leak

Threat actors repurposed leaked Kryptina ransomware source code to create Mallox Linux 1.0. The core functionality, including AES-256 CBC encryption and OpenSSL decryption, remains unchanged. 

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Registration

While Kryptina branding is removed from most files, references persist in function names (e.g., krptna_process_file) within the /src folder. Mallox includes a stripped-down version of the original Kryptina documentation translated into Russian. 

Ransomware note templates were modified to reflect Mallox branding. The core encryptor source file (kryptina. c) retains the original Kryptina name but has comments and debug messages updated for Mallox. 

Similarly, the scripting_demo.py script used for automated payload builds was minimally modified to remove Kryptina references.  

Kryptina database in Mallox leak
Kryptina database in Mallox leak

The Kryptina and Mallox makefiles are used to build encryptor and decryptor payloads. Both makefiles offer various build modes, including demo, debug, symbols, and arch32. Additional parameters can also be customized for XOR key, thread count, self-deletion, filesize constraints, and secure deletion. 

The Mallox makefile introduces new parameters for payload type (crypto or decryptor), compression level, and the ability to include a custom payload header. Both makefiles allow for flexible payload configuration based on specific requirements.

Kryptina makefile
Kryptina makefile

The May 2024 affiliate leak exposed a trove of target-specific data, including 14 potential victim subfolders containing config.json files and compiled encryptor/decryptor tools with identical payment addresses and ransom note templates. 

According to Sentinel Labs, the config files contained specific details such as payment type, addresses, and ransom note content, indicating a coordinated and targeted attack campaign.

Mallox malware uses leaked affiliate servers to target Windows systems. The server contains various tools for initial compromise, including an exploit for CVE-2024-21338 (Windows privilege escalation) and a tool to disable Kaspersky endpoint products. 

They are also found on the server, including PowerShell scripts and a JAR file that launches a PowerShell script to download Mallox.

The server also contains a full offline installer of Java JRE and additional dropper/payload sets for 32-bit and 64-bit systems.  

Analyse AnySuspicious Links Using ANY.RUN's New Safe Browsing Tool: Try It for Free

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

OpenVPN Flaw Allows Attackers Crash Servers and Run Remote Code

OpenVPN, a widely-used open-source virtual private network (VPN) software, has recently patched a security...

Apache Traffic Server Flaw Allows Request Smuggling Attacks

A critical vulnerability has been discovered in Apache Traffic Server (ATS), an open-source caching...

Secure Ideas Achieves CREST Accreditation and CMMC Level 1 Compliance

Secure Ideas, a premier provider of penetration testing and security consulting services, proudly announces...

New Phishing Campaign Targets Investors to Steal Login Credentials

Symantec has recently identified a sophisticated phishing campaign targeting users of Monex Securities (マネックス証券),...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

OpenVPN Flaw Allows Attackers Crash Servers and Run Remote Code

OpenVPN, a widely-used open-source virtual private network (VPN) software, has recently patched a security...

Apache Traffic Server Flaw Allows Request Smuggling Attacks

A critical vulnerability has been discovered in Apache Traffic Server (ATS), an open-source caching...

New Phishing Campaign Targets Investors to Steal Login Credentials

Symantec has recently identified a sophisticated phishing campaign targeting users of Monex Securities (マネックス証券),...