Weaxor — Ransomware Profile

Weaxor is the current payload name of the ransomware-as-a-service operation that first appeared in mid-2021 as TargetCompany and became widely known as Mallox. K7 Labs reports the group renamed the payload in late 2024 to shed detection profiles built around the older names, while keeping its long-standing focus on enterprise database servers, above all internet-exposed Microsoft SQL Server deployments protected by weak administrative credentials. A 2026 intrusion analysed by K7 Labs shows the operation has moved from noisy on-disk deployment to a largely memory-resident chain: the database engine itself is used to run operating system commands, an obfuscated PowerShell loader disables script scanning and pulls a stager, a Cobalt Strike Beacon runs in memory, and the encryptor is injected into the signed SQLPS.exe utility before encrypting files with ChaCha20 and appending a .weax extension.

Also tracked as

Mallox, TargetCompany, FARGO, Xollam, Water Gatpanapun, Tohnichi

IntelFusions coverage (1)

Tools & malware

Vendor research

Read the full analysis on IntelFusions