Avast has developed and released a free decryption tool for the Mallox ransomware.
The tool is based on an issue in the ransomware payload's cryptographic schema, reports Security Week. A Mallox ransomware attack, which primarily target Windows system, would begin with the delivery of droppers and scripts to escalate privileges and download the ransomware, which conducts file encryption using the ChaCha20 algorithm before injecting the ransom note.
After ending SQL database-related processes and encrypting data storage-related files, Mallox ransomware proceeds with system file locking, automatic repair defense deactivation, and shadow copy removal.
"The crypto-flaw was fixed around March 2024, so it is no longer possible to decrypt data encrypted by the later versions of Mallox ransomware," said Avast.
Written by
Dan Raywood
Senior Editor
SC Media UK
Dan Raywood is a B2B journalist with more than 20 years of experience, including covering cybersecurity for the past 16 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.
He has spoken at events including 44CON, Infosecurity Europe, RANT Conference, BSides Scotland, Steelcon and ESET Security Days.
Outside work, Dan enjoys supporting Tottenham Hotspur, managing mischievous cats, and sampling craft beers.