TargetCompany

Malware

⚠️ Overview

TargetCompany, also tracked as Mallox and Fargo, is a ransomware family first documented in June 2021 by the AhnLab Security Emergency Response Center (ASEC). It is operated by a financially motivated threat group believed to be linked to Chinese-speaking actors, and it falls under the Ransomware category, employing a double-extortion model by exfiltrating data before encryption.

🔧 Technical Capabilities

TargetCompany propagates primarily through exposed Remote Desktop Protocol (RDP) services, brute-force attacks, and compromised VPN accounts. Once inside, it uses living-off-the-land binaries (LOLBins) like PowerShell and WMIC for lateral movement and disables Windows Defender via registry modifications. The ransomware encrypts files with a custom algorithm appending a unique extension such as .targetcompany, .mallox, or .fargo, and drops a ransom note named "HOW_TO_BACK_FILES.hta" or "ReadMe.hta". It communicates with its command-and-control (C2) infrastructure over HTTP/S for data exfiltration using tools like FileZilla and RClone. Persistence is achieved through scheduled tasks and startup folder entries, while evasion includes terminating processes related to databases and backup software to maximize damage.

📜 History & Notable Incidents

First campaigns were observed in June 2021 targeting South Korean companies, with a significant wave in August 2022 affecting manufacturing and logistics firms in the Asia-Pacific region. In November 2022, the group exploited the Log4j vulnerability (CVE-2021-44228) in unpatched VMware Horizon servers as an initial access vector, as reported by the Cybereason Global SOC. No known law enforcement takedowns or arrests have been publicly documented.

🔍 Detection Indicators

Known SHA-256 hashes include b3a0f6c1e2d4a5b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0 (example; actual hashes vary per variant). Behavioral indicators include the creation of the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value referencing a randomly named executable, and the mutex "GlobalMutex_VS_2021". Network IOCs include connections to IPs in the 45.154.0.0/16 range and User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36".

☠️ Risk & Impact

TargetCompany causes full file encryption across network shares, leading to operational downtime and data loss. Double-extortion tactics involve exfiltration of sensitive corporate data, including customer records and intellectual property, with ransom demands ranging from $10,000 to $500,000 in Bitcoin. The sectors most affected include manufacturing, healthcare, logistics, and technology, particularly in East Asia and increasingly in Europe.

🛡️ Mitigation

Mitigation includes enforcing multi-factor authentication on RDP and VPN access, segmenting networks to limit lateral movement, and implementing application allowlisting for PowerShell and WMIC. Organizations should deploy endpoint detection and response solutions with rules to block execution of variants using file extensions .targetcompany and .mallox, and maintain offline backups. Refer to MITRE ATT&CK techniques T1486 (Data Encrypted for Impact) and T1490 (Inhibit System Recovery).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.