Skip to content

Xorist

Xorist is a long-running Windows ransomware family known for encrypting victim files and demanding payment for decryption.

Profile source: Mallory opens in a new tab

Xorist

Family profile

Xorist is a long-running Windows ransomware family known for encrypting victim files and demanding payment for decryption. It has been widely tracked under Win32 ransomware naming conventions and has appeared in multiple campaigns and variants over time. Xorist is notable both as an established family in its own right and as a code lineage associated with later ransomware operations, including assessments linking MortalKombat to the Xorist family based on code and implementation similarities.

Xorist targets Windows systems and is associated with typical ransomware behaviors including file encryption, ransom-note creation, and user-impacting system changes. Reporting tied to Xorist-family activity indicates persistence mechanisms through autorun configuration, and some variants or related descendants have altered the desktop environment and impaired normal system usability after encryption. Xorist has also been referenced in connection with email-borne ransomware delivery, indicating that phishing or malspam can serve as an access vector in at least some campaigns.

The family has remained sufficiently prevalent and recognizable to be included in major ransomware tracking and recovery efforts, and publicly available decryptors exist for at least some Xorist variants. Xorist has also surfaced in comparative analysis of other malware, including overlap in ransom-note contact details seen in unrelated destructive malware masquerading as ransomware, though such overlap alone does not establish operational identity. Overall, Xorist is best understood as a well-known Windows ransomware family with multiple variants, recurring criminal use, and a history of both direct ransomware deployment and code-family reuse in later campaigns.

Capabilities

  • Extortion
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 11, 2026
Last activity
Sep 11, 2026
Feed role
C2
Host form
4 IP / 0 hostnames

Leading locations

  • HK2
  • US2

Leading providers

  • ChangLian Network Technology Co., Limited1
  • Cox Communications Inc.1
  • Hong Kong Communications International Co., Limited1
  • XNNET LLC1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

MITRE ATT&CK

Xorist in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.