Description Summary
This ransomware uses a combination of different crypto algorithms (ChaCha20, AES-128, Curve25519). The activity of this malware is dated to mid-June 2021. The extension of the encrypted files are set to the compromised company: .
Threat Actor
'TargetCompany/FARGO/Tohnichi' operators; access primarily via brute-force of exposed MS-SQL/PostgreSQL servers.
Technical Indicators
Encryption Extension
.mallox / .<target_company>
Encryption Algorithm
ChaCha20 + AES-128 + Curve25519
Ransom Note Name
HOW TO RESTORE FILES.txt / FILE RECOVERY.txt
Targeted Industries
Manufacturing, Professional services, Retail
First Seen
June 2021
Last Seen
Active
Geographical Location
Worldwide (heavy in Asia/India)
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| Exfiltration x 1 | T1567 | Exfiltration Over Web Service (leak site) |
| Initial Access x 2 | T1190 | Exploit Public-Facing Application |
| T1078 | Valid Accounts |