Exorcist
Exorcist is Windows ransomware first reported in July 2020.
Profile source: Hatching opens in a new tabExorcist
Family profile
Exorcist is Windows ransomware first reported in July 2020. Its operators later released Exorcist 2.0 with changes to its configuration, encryption process, ransom note, and payment site.
Operational record
Reporting
Research mentioning Exorcist
A new APT uses DLL side-loads to “KilllSomeOne” | SOPHOS
Sophos has identified a new PlugX USB worm variant spreading through removable media in outbreaks across Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria, using DLL sideloading with legitimate AvastSvc.exe, a malicious wsc.dll, and an encrypted PlugX payload. The malware hides files on infected USB drives, gathers host reconnaissance, and steals Office and PDF documents up to 300 MB, storing them in encrypted form under RECYCLER.BIN with base64-obfuscated filenames before attempting exfiltration to infrastructure including 45.142.166[.]112. The activity aligns with the long-running PKPLUG espionage cluster, which researchers have previously attributed with high confidence to a Chinese nation-state adversary targeting victims in and around Southeast Asia, including Xinjiang, Mongolia, Myanmar, and Taiwan. Earlier reporting tied PKPLUG to malware families including PlugX, Poison Ivy, 9002, Zupdax, Farseer, and the Android spyware HenBox, and documented overlapping infrastructure, DLL sideloading, registry-based persistence, and surveillance-focused collection against regional targets, reinforcing the assessment that the new worm is part of a broader intelligence-gathering campaign.
A border-hopping PlugX USB worm takes its act on the road | SOPHOS
Chinese PlugX Malware Hidden in Your USB Devices?
Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike
Farseer: Previously Unknown Malware Family bolsters the Chinese armoury
Attackers used spear-phishing emails with TinyURL links and an actor-controlled redirection server to deliver the 9002 Trojan from a Google Drive-hosted ZIP archive. The redirection chain embedded a target email address and destination URL in base64-encoded parameters, apparently to track victim clicks, and one lure targeted a legitimate Myanmar politician and human rights activist. The downloaded executable posed as a PowerPoint file, displayed a Myanmar-related conference decoy, and installed malware through DLL sideloading by abusing a legitimate RealNetworks executable. Researchers linked the campaign’s infrastructure and beaconing artifacts to broader activity associated with Poison Ivy, PlugX, Zupdax, HenBox, and the later-identified Farseer malware family. Farseer shared tradecraft including DLL sideloading with signed binaries, encrypted and compressed payloads, obfuscated configuration data, registry persistence, and command-and-control over domains such as update.tcpdo[.]net, honor2020[.]ga, and up.outhmail[.]com. The overlapping infrastructure and Myanmar- and Southeast Asia-themed lures indicate a sustained intrusion set focused on targets in Myanmar, Taiwan, and the wider region.