Weaxor — Ransomware Profile
Weaxor is the current payload name of the ransomware-as-a-service operation that first appeared in mid-2021 as TargetCompany and became widely known as Mallox. K7 Labs reports the group renamed the payload in late 2024 to shed detection profiles built around the older names, while keeping its long-standing focus on enterprise database servers, above all internet-exposed Microsoft SQL Server deployments protected by weak administrative credentials. A 2026 intrusion analysed by K7 Labs shows the operation has moved from noisy on-disk deployment to a largely memory-resident chain: the database engine itself is used to run operating system commands, an obfuscated PowerShell loader disables script scanning and pulls a stager, a Cobalt Strike Beacon runs in memory, and the encryptor is injected into the signed SQLPS.exe utility before encrypting files with ChaCha20 and appending a .weax extension.Also tracked as
Mallox, TargetCompany, FARGO, Xollam, Water Gatpanapun, Tohnichi
IntelFusions coverage (1)
- Weaxor ransomware turns SQL Server into its launchpad 2026-08-13 · Ransomware
Tools & malware
- AnyDesk Remote access software
- Cobalt Strike Post-exploitation framework
- GMER Anti-rootkit utility
- Mimikatz Credential dumper
- Negasteal Information stealer
- PureCrypter Loader
- Remcos Remote access trojan
- Snake Keylogger Keylogger
- YDArk Rootkit utility
Vendor research
- Weaxor: Rebranded Mallox Ransomware with a Unique Payload Delivery Method Seqrite
- TargetCompany's Linux Variant Targets ESXi Environments Trend Micro
- Ransomware Spotlight: TargetCompany Trend Micro
- Mallox affiliate leverages PureCrypter in MS-SQL exploitation campaigns Sekoia
- React2Shell used as initial access vector for Weaxor ransomware deployment S-RM
- When SQL Server Becomes the Initial Launcher: A Deep Dive into Weaxor Ransomware Execution K7 Labs
- Threat Group Assessment: Mallox Ransomware Unit 42