Ransomware Group intelligence
Malas
InactiveTrack Malas with 170 published victims and 1 known leak locations in a single intelligence view.
Overview
Malas is tracked by Breach House as a ransomware group with 170 published victims.
Russian Federation is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 2h ago | malas2urovbyyavjzaezkt5ohljvyd5lt7vv7mnsgbf2y4bwlh72doqd.onion |
Top Activity Sectors (12)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Malas, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: malas executes malicious commands via PowerShell scripts to stage payloads and manipulate system processes.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: malas leverages native API calls to interact with Windows services and evade detection during initial execution.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: malas disables antivirus tools and security software to prevent system recovery and hinder forensic analysis.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: malas encodes and encrypts command-and-control payloads to avoid static detection by security tools.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: malas deletes Volume Shadow Copies and critical system files to ensure data recovery becomes impossible.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1110 Brute Force Credential Access
What they do: malas brute-forces local usernames and passwords to gain initial access to networked systems.
What that means: Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
-
T1049 System Network Connections Discovery Discovery
What they do: malas queries system network connections to identify high-value targets and communication paths for exfiltration.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: malas uses SMB/Windows Admin Shares to propagate payloads across internal networks to additional victims.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1486 Data Encrypted for Impact Impact
What they do: malas encrypts victim files using custom ransomware binaries, locking data for extortion demands.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: malas runs scripts to inhibit system recovery processes, preventing automatic restoration of encrypted files.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (170)
Search, filter and paginate the victim timeline for Malas. Showing 101–170 of 170.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ISONA GmbH id101 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Терра-Минора id102 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Азимут НТ id103 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | BenarIT id104 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Asanger Modellbau id105 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Iris Key Solutions id106 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Невский Альянс id107 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | NTD SA id108 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ATE Elettronica id109 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Answerpro id110 View details | Communication / Marketing | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Onubo s.r.l. id111 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Гис Нефтесервис id112 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Commerciale Ferramenta id113 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | KomGarant id114 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Froese & Partner id115 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | BMW Алдис id116 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ВК Логистик id117 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | SBG Global id118 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Winner Italia id119 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | SA.FI id120 View details | Finland | Other | ||
|
using Zimbra vulnerability |
|||||
| Ransomware | Rivas Boquete SL id121 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | TitanPower id122 View details | Energy | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Qball Technologies id123 View details | IT | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Villa Grazioli id124 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Accurate Section Benders id125 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | INFINREAL Immobilien GmbH id126 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Evology Manufacturing id127 View details | Manufacturing / Engineering | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Omniglobe Business Solutions id128 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | happy-snack.ru id129 View details | Russian Federation | Other | ||
|
using Zimbra vulnerability |
|||||
| Ransomware | Loeje Trust SA id130 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Legato id131 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Boarding Concept id132 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | NEXT OS id133 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | International Cargo Equipment id134 View details | Transportation / Travel / Logistics | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | NTA srl id135 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Altarix id136 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Confindustria Energia id137 View details | Italy | Other | ||
|
using Zimbra vulnerability |
|||||
| Ransomware | TBIT Services id138 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | JvG Consulting id139 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | FinRe Consulting id140 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | RusExport Ltd id141 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Next Generation Srl id142 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Wishmaster id143 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Business Travel Solutions id144 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Гудвин-Нева id145 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Etanova id146 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Studio Papa id147 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | reg22 id148 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Hotel Smeraldo id149 View details | Hospitality / Food & Beverage / Tourism | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Chiltern Networks id150 View details | Telecommunications | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | radiosvet id151 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Wpat id152 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Spectris Business Systems id153 View details | Services | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Мебельснаб id154 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Orcutt Winslow id155 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Mangum Construction id156 View details | Construction / Real Estate | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | AMET id157 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Preference Portugal id158 View details | Communication / Marketing | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Км Профиль id159 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Livitek id160 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Chernoff Thompson Architects id161 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Dalim Software GmbH id162 View details | IT | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Propac S.r.l. id163 View details | Communication / Marketing | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | MetaContratas id164 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | ISG Software Group id165 View details | IT | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | еКредит id166 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | IPG Automotive GmbH id167 View details | Manufacturing / Engineering | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | AViSTO id168 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | BeeVoip id169 View details | Other | |||
|
using Zimbra vulnerability |
|||||
| Ransomware | Anstel id170 View details | Other | |||
|
using Zimbra vulnerability |
|||||