• About
  • Privacy Policy
Open Security Labs
No Result
View All Result
No Result
View All Result
Open Security Labs
No Result
View All Result
Home Uncategorized

New Mallox Ransomware variant – A danger to VMWare ESXi Environments (0)

Hriday Nakka by Hriday Nakka
14th June 2024
in Uncategorized
0
Mallox Ransomware
473
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
  1. Mallox Ransomware’s Sophisticated Attack Technique on VMWare ESXi Systems
  2. Use of Custom Shell Script
  3. Detailed Operation of the Mallox Variant
  4. Implications for Linux ESXi Environments
  5. Recommended Cybersecurity Measures
    1. Enable Multi-Factor Authentication (MFA):
    2. Adopt the 3-2-1 Backup Rule:
    3. Regular Patching and Updates:
    4. Implement Strong Access Controls:
    5. Monitor Network Activity:
    6. Employee Training:
  6. Conclusion

A novel attack vector by the Mallox ransomware group targets VMWare ESXi environments, focusing on systems with administrative privileges. This new variant uses a custom shell script for payload delivery and execution, highlighting a sophisticated approach to ransomware attacks.

Mallox Ransomware’s Sophisticated Attack Technique on VMWare ESXi Systems

Discovered by researchers at Trend Micro, this Linux variant of Mallox ransomware specifically targets systems running in a VMWare ESXi environment with administrative rights. If these conditions are not met, the ransomware does not proceed with the attack. Mallox, also known as Fargo and Tohnichi, has been active since June 2021, targeting sectors such as manufacturing, retail, wholesale, legal, and professional services. This year, the group has been particularly active in Taiwan, India, Thailand, and South Korea.

Use of Custom Shell Script

The Linux variant marks the first instance of Mallox using a custom shell script to deliver and execute ransomware in virtualized environments. This approach aims to create more disruption, increasing the likelihood of ransom payments. The variant’s custom shell script also exfiltrates victim information to two different servers, providing a backup of the stolen data.

Detailed Operation of the Mallox Variant

The Mallox variant first checks if the targeted system has administrative rights. If not, it halts its activity. Upon execution, it drops a text file named TargetInfo.txt, which contains victim information sent to a command-and-control (C2) server. The researchers noted that the IP address used for exfiltrating this information and later executing the payload was new and hosted by China Mobile Communications.

The variant also checks if the machine is running in a VMWare ESXi environment by identifying if the system name matches “vmkernel.” If confirmed, it deploys its encryption routine, appending the extension “.locked” on encrypted files and dropping a ransom note named HOW TO DECRYPT.txt. This extension and note differ from the Windows variant.

The custom shell script not only downloads and executes the payload but also exfiltrates data to another server by reading the contents of the dropped text file. This dual-server exfiltration enhances redundancy, ensuring that data remains accessible even if one server goes offline.

Implications for Linux ESXi Environments

The expansion of Mallox’s attack activities into Linux environments running VMware ESXi highlights the need for heightened vigilance. Organizations using such environments must implement robust cybersecurity measures to mitigate the risk of ransomware attacks and protect data integrity.

Recommended Cybersecurity Measures

To defend against sophisticated ransomware like Mallox, organizations should:

Enable Multi-Factor Authentication (MFA):

This prevents attackers from moving laterally within a network.

Adopt the 3-2-1 Backup Rule:

Create three backup copies on two different formats, with one copy stored offsite.

Regular Patching and Updates:

Keeping systems updated can prevent exploitation of software vulnerabilities.

Implement Strong Access Controls:

Limit administrative privileges to reduce the attack surface.

Monitor Network Activity:

Continuous monitoring can detect unusual activities early, allowing for swift responses.

Employee Training:

Educate employees on recognizing phishing attempts and other common attack vectors.

    Conclusion

    The Mallox ransomware group’s sophisticated tactics, particularly its new Linux variant targeting VMWare ESXi environments, underscore the evolving nature of cyber threats. By implementing comprehensive security measures and staying vigilant, organizations can better protect themselves from such advanced ransomware attacks. Continuous monitoring, regular updates, and robust backup strategies are crucial in mitigating the risks and ensuring the security of critical systems and data.

    VMware

    Share this:

    • Share on X (Opens in new window) X
    • Share on Facebook (Opens in new window) Facebook
    • Share on LinkedIn (Opens in new window) LinkedIn
    • Share on Telegram (Opens in new window) Telegram
    • Share on WhatsApp (Opens in new window) WhatsApp
    • Share on Mastodon (Opens in new window) Mastodon
    • Email a link to a friend (Opens in new window) Email

    Related


    Discover more from Open Security Labs

    Subscribe to get the latest posts sent to your email.

    Previous Post

    Coordinated Cyber Espionage Campaign by Chinese Hacking Groups

    Next Post

    2024 Paris Olympics Under Threat: Cybersecurity Concerns and State-Sponsored Threat Actors

    Related Posts

    CyberStalking
    Uncategorized

    The Dark Reality of Cyberstalking: How to Stay Safe on Social Media (0penBuckets)

    29th December 2024
    Volkswagen
    Uncategorized

    Massive Data Exposure from Volkswagen Electric Cars Highlights Cloud Security Risks (0penBuckets)

    29th December 2024
    amazon
    Uncategorized

    Dangerous Android Malware Found on Amazon Appstore – Steals Your Data in Disguise! (0penBuckets)

    21st December 2024
    Live Sports
    Uncategorized

    Massive Live Sports Piracy Ring Shut Down – Over 821 Million Visits Annually!”

    21st December 2024
    BellaCPP
    Uncategorized

    BellaCPP: The C++ Malware That’s Redefining Cyber Threats (0penBuckets)

    21st December 2024
    Docker
    Uncategorized

    Mastering Docker Security: Essential Tips for Unbreakable Containers (0penBuckets)

    21st December 2024
    Next Post
    paris

    2024 Paris Olympics Under Threat: Cybersecurity Concerns and State-Sponsored Threat Actors

    Leave a ReplyCancel reply

    • About
    • Privacy Policy

    © 2024 OpenSecurityLabs.com

    No Result
    View All Result
    • About
    • Privacy Policy

    © 2024 OpenSecurityLabs.com

    Discover more from Open Security Labs

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    Discover more from Open Security Labs

    Subscribe now to keep reading and get access to the full archive.

    Continue reading

    Loading Comments...