Header image

Mallox Ransomware Decryption Tool Released

Avast release free tool.

Avast has developed and released a free decryption tool for the Mallox ransomware.

The tool is based on an issue in the ransomware payload's cryptographic schema, reports Security Week. A Mallox ransomware attack, which primarily target Windows system, would begin with the delivery of droppers and scripts to escalate privileges and download the ransomware, which conducts file encryption using the ChaCha20 algorithm before injecting the ransom note.

After ending SQL database-related processes and encrypting data storage-related files, Mallox ransomware proceeds with system file locking, automatic repair defense deactivation, and shadow copy removal.

"The crypto-flaw was fixed around March 2024, so it is no longer possible to decrypt data encrypted by the later versions of Mallox ransomware," said Avast.

Dan Raywood
Dan Raywood

Dan Raywood is a B2B journalist with 25 years of experience, including covering cybersecurity for the past 17 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Forum, BSides Scotland, Steelcon and the National Cyber Security Show, and served as editor of SC Media UK, Infosecurity Magazine and IT Security Guru. He was also an analyst with 451 Research and a product marketing lead at Tenable.

Dan Raywood
Dan Raywood

Dan Raywood is a B2B journalist with 25 years of experience, including covering cybersecurity for the past 17 years. He has extensively covered topics from Advanced Persistent Threats and nation-state hackers to major data breaches and regulatory changes.

He has spoken at events including 44CON, Infosecurity Europe, RANT Forum, BSides Scotland, Steelcon and the National Cyber Security Show, and served as editor of SC Media UK, Infosecurity Magazine and IT Security Guru. He was also an analyst with 451 Research and a product marketing lead at Tenable.

Upcoming Events

No events found.