Ransomware Group intelligence
Malas
InactiveTrack Malas with 170 published victims and 1 known leak locations in a single intelligence view.
Overview
Malas is tracked by Breach House as a ransomware group with 170 published victims.
Russian Federation is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 9m ago | malas2urovbyyavjzaezkt5ohljvyd5lt7vv7mnsgbf2y4bwlh72doqd.onion |
Top Activity Sectors (12)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Malas, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: malas executes malicious commands via PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: malas leverages native API calls to interact with Windows services and evade detection during initial execution.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: malas disables antivirus tools and security software to prevent system recovery and hinder forensic analysis.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: malas encodes and encrypts command-and-control payloads to avoid static detection by security tools.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: malas deletes Volume Shadow Copies and critical system files to ensure data recovery becomes impossible.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: malas brute-forces local usernames and passwords to gain initial access to networked systems.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1049 System Network Connections Discovery Discovery
What they do: malas queries system network connections to identify high-value targets and communication paths for exfiltration.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: malas uses SMB/Windows Admin Shares to propagate payloads across internal networks to additional victims.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: malas encrypts victim files using custom ransomware binaries, locking data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: malas runs scripts to inhibit system recovery processes, preventing automatic restoration of encrypted files.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (170)
Search, filter and paginate the victim timeline for Malas. Showing 1–100 of 170.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Fort Rolins Collection Agency id6461 View details | Indonesia | Communication / Marketing | ||
|
<p>They act like they don&rsquo;t see🙈 our ransom note🗒 , or they just don&rsquo;t negotiate🤝with cyberterrorists💣. They restore their backups and think ignoring us🙉 makes us go away. So now we also restore their backups, for all of you.</p> <p>Harita Group is dedicated to mining, logging rainforests🐒😭 to plant palm oil monocultures, coal, and anything else that&rsquo;ll make them a profit through destroying their countries&rsquo; environment. Their Swiss🇨🇭🇭 partner Glencore is well documented for it&rsquo;s human rights and environmental abuses in Latin America, including hiring paramilitary killers to drive indigenous off their lands so they can steal it. We think it&rsquo;s likely they operate the same in Indonesia and journalists will like to look through their emails |
|||||
| Ransomware | Compañía Agricola San Felipe id6460 View details | Agriculture / Food | |||
|
<p>Your work is collecting and repossessing from struggling people? Don&rsquo;t complain when we come to repossess your own files |
|||||
| Ransomware | Banco Azzoaglio id3 View details | Italy | Finance / Legal / Insurance | ||
|
using Zimbra vulnerability |
|||||
| Ransomware | Ларина id4 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Utair id5 View details | Russian Federation | Other | ||
|
using Zimbra vulnerability |
|||||
| Ransomware | The Sound Organisation id6 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Angle Metal Mfg. id7 View details | Manufacturing / Engineering | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Красный Восток Агро id8 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Petromiralles id9 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | nanoCAD id10 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Baggio id11 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ЖБИ2-Инвест id12 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Город Кафе id13 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Diete-Siepmann id14 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Fitser id15 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | MHWEB id16 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Pergler id17 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Имеди id18 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Altia id19 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Евроэкспо id20 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Aster Cucine id21 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | KondorCS id22 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ФГУП “ЦНИИХМ” id23 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Custom Manufacturing & Engineering, Inc id24 View details | Manufacturing / Engineering | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Копчёнов id25 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ArCloud id26 View details | IT | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Гласс Фурнитура id27 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | LunarWeb id28 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Oasis Ads Media id29 View details | Communication / Marketing | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Azzurra Group id30 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ConnectTo id31 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Сервиста id32 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Amersport id33 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Studio Negri e Associati id34 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Hoteles Globales id35 View details | Hospitality / Food & Beverage / Tourism | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | HostingPerTe id36 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Sita Software id37 View details | IT | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Exset id38 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Fraport Skyliners id39 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | D&G impianti elettrici id40 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | RepcoLite id41 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Sallemi Carburanti id42 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | BEI Srl id43 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Bicom id44 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Transitus Group id45 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | spw.ru id46 View details | Russian Federation | Other | ||
|
using Zimbra vulnerability |
|||||
| Ransomware | Mappy Italia id47 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | cashbackAPP id48 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Bleu Blanc id49 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | KriaaNet Inc id50 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Hardman’s id51 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Ямалтелеком id52 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Baur Hausverwaltung id53 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Grupo Fatecsa id54 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | InfinCE id55 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | SkyFORS id56 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Balbi Srl id57 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Steelgroup id58 View details | Manufacturing / Engineering | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | СКППК id59 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | DSSL id60 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Kouros id61 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Johnston Technical Services id62 View details | IT | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | BE.iT SA id63 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Horseman Sim id64 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Zite Media id65 View details | Communication / Marketing | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Трансбалт id66 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Формекс id67 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Pasquetti Sarti & Partners id68 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Herold Druck id69 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | paulmitchell.ru id70 View details | Russian Federation | Other | ||
|
using Zimbra vulnerability |
|||||
| Ransomware | Nu-Pro Group id71 View details | United Kingdom | Communication / Marketing | ||
|
using Zimbra vulnerability |
|||||
| Ransomware | Studio Eco Perucca id72 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Axon Certified Auditors id73 View details | Finance / Legal / Insurance | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Studio Rossetti e Partners id74 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Riboli srl id75 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | meta-spb id76 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Studio Consulenza id77 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | 3Punto6 id78 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Gallagher & Co Consultants id79 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Evropoly id80 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Псковпассажиравтотранс id81 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Cosmos Hotel Group id82 View details | Hospitality / Food & Beverage / Tourism | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ICT-LabS id83 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Mobalpa Biarritz id84 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | FEA srl id85 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Grassi srl id86 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Tycoon Group id87 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Fresh-Heads IT id88 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Vegliolux id89 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | AVM Software & Technology id90 View details | IT | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ТрансКом-Авиа id91 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Specialinsert id92 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Totality Solutions id93 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | СК БлагоДать id94 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Астра id95 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Универсалресурс id96 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | TCG id97 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | PMP Meccanica id98 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Axon id99 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | OPIT Solutions id100 View details | Services | |||
|
using Zimbra vulnerability |
|||||