Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Malas

Malas is a lesser-documented ransomware group that maintains an active dark web presence; detailed information about its targets, victims, or operational model is limited in public reporting.

Victims
170
 
First Discovered
2023-04-09
victim
Last Discovered
2023-05-18
victim
Inactive Since
2yrs
more than
Avg Delay
39
days
Infostealer
16.7%
victims with domain
Countries
5
hit
View Victims on World Map View Group Statistics

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Yes 2026-05-13T20:13:43 NGINX nginx 1.18.0 malas2urovbyyavjzaezkt5ohljvyd5lt7vv7mnsgbf2y4bwlh72doqd.onion

Target
Top 5 Activity Sectors
  • Business Services 52
  • Manufacturing 33
  • Technology 27
  • Consumer Services 15
  • Transportation/Logistics 8
Top 5 Countries
  • RU flag Russian Federation 4
  • IT flag Italy 2
  • ID flag Indonesia 1
  • FI flag Finland 1
  • GB flag United Kingdom 1

Heatmap

YARA Rules (1)

Victims (170)
Logo
Discovered: 2023-05-18 (2y ago)  ·  Attack est.: 2023-04-09
<p>They act like they don’t see🙈 our ransom note🗒 , or they just don’t neg…
Logo
Discovered: 2023-05-18 (2y ago)  ·  Attack est.: 2023-04-09
<p>Your work is collecting and repossessing from struggling people? Don’t complain w…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…
Logo
Discovered: 2023-04-09 (3y ago)
using Zimbra vulnerability…