Skip to content

Exorcist

Exorcist is Windows ransomware first reported in July 2020.

Profile source: Hatching opens in a new tab

Exorcist

Family profile

Exorcist is Windows ransomware first reported in July 2020. Its operators later released Exorcist 2.0 with changes to its configuration, encryption process, ransom note, and payment site.

Operational record

1
YARA rules
1
Leak sites
0 available

Reporting

Research mentioning Exorcist

Jan 1
Sophos Threat Research

A new APT uses DLL side-loads to “KilllSomeOne” | SOPHOS

Sophos has identified a new PlugX USB worm variant spreading through removable media in outbreaks across Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria, using DLL sideloading with legitimate AvastSvc.exe, a malicious wsc.dll, and an encrypted PlugX payload. The malware hides files on infected USB drives, gathers host reconnaissance, and steals Office and PDF documents up to 300 MB, storing them in encrypted form under RECYCLER.BIN with base64-obfuscated filenames before attempting exfiltration to infrastructure including 45.142.166[.]112. The activity aligns with the long-running PKPLUG espionage cluster, which researchers have previously attributed with high confidence to a Chinese nation-state adversary targeting victims in and around Southeast Asia, including Xinjiang, Mongolia, Myanmar, and Taiwan. Earlier reporting tied PKPLUG to malware families including PlugX, Poison Ivy, 9002, Zupdax, Farseer, and the Android spyware HenBox, and documented overlapping infrastructure, DLL sideloading, registry-based persistence, and surveillance-focused collection against regional targets, reinforcing the assessment that the new worm is part of a broader intelligence-gathering campaign.

Jan 1
Sophos Threat Research

A border-hopping PlugX USB worm takes its act on the road | SOPHOS

Jan 26
Palo Alto Networks Unit 42

Chinese PlugX Malware Hidden in Your USB Devices?

Oct 12
Trendmicro

Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike

Feb 26
Palo Alto Networks Unit 42

Farseer: Previously Unknown Malware Family bolsters the Chinese armoury

Attackers used spear-phishing emails with TinyURL links and an actor-controlled redirection server to deliver the 9002 Trojan from a Google Drive-hosted ZIP archive. The redirection chain embedded a target email address and destination URL in base64-encoded parameters, apparently to track victim clicks, and one lure targeted a legitimate Myanmar politician and human rights activist. The downloaded executable posed as a PowerPoint file, displayed a Myanmar-related conference decoy, and installed malware through DLL sideloading by abusing a legitimate RealNetworks executable. Researchers linked the campaign’s infrastructure and beaconing artifacts to broader activity associated with Poison Ivy, PlugX, Zupdax, HenBox, and the later-identified Farseer malware family. Farseer shared tradecraft including DLL sideloading with signed binaries, encrypted and compressed payloads, obfuscated configuration data, registry persistence, and command-and-control over domains such as update.tcpdo[.]net, honor2020[.]ga, and up.outhmail[.]com. The overlapping infrastructure and Myanmar- and Southeast Asia-themed lures indicate a sustained intrusion set focused on targets in Myanmar, Taiwan, and the wider region.

Jul 26
Paloalto Researchcenter Historic

Attack Delivers ‘9002’ Trojan Through Google Drive

Apr 21
Virusbulletin

Virus Bulletin :: VB2019 paper: Pulling the PKPLUG: the adversary playbook for the long-standing espionage activity of a Chinese nation-state adversary

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.