Last seven days
- First activity
- Sep 11, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2
- Host form
- 4 IP / 0 hostnames
Xorist is a long-running Windows ransomware family known for encrypting victim files and demanding payment for decryption.
Profile source: Mallory opens in a new tabXorist
Xorist is a long-running Windows ransomware family known for encrypting victim files and demanding payment for decryption. It has been widely tracked under Win32 ransomware naming conventions and has appeared in multiple campaigns and variants over time. Xorist is notable both as an established family in its own right and as a code lineage associated with later ransomware operations, including assessments linking MortalKombat to the Xorist family based on code and implementation similarities.
Xorist targets Windows systems and is associated with typical ransomware behaviors including file encryption, ransom-note creation, and user-impacting system changes. Reporting tied to Xorist-family activity indicates persistence mechanisms through autorun configuration, and some variants or related descendants have altered the desktop environment and impaired normal system usability after encryption. Xorist has also been referenced in connection with email-borne ransomware delivery, indicating that phishing or malspam can serve as an access vector in at least some campaigns.
The family has remained sufficiently prevalent and recognizable to be included in major ransomware tracking and recovery efforts, and publicly available decryptors exist for at least some Xorist variants. Xorist has also surfaced in comparative analysis of other malware, including overlap in ransom-note contact details seen in unrelated destructive malware masquerading as ransomware, though such overlap alone does not establish operational identity. Overall, Xorist is best understood as a well-known Windows ransomware family with multiple variants, recurring criminal use, and a history of both direct ransomware deployment and code-family reuse in later campaigns.
C2 tracking
Derp observations, rolling seven-day window
Samples
0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 27215e26b312b8b4f8fc51bdcea6741536dafc9267348284e2259e798aed0e4d 3755718db9d33f4aba2563de454d4530a308b41b1096c904102d08e2101f2020 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 738eacc140159cd81dff41dd16c806eb7c0c8391c256f1738d75d0321f77ba2e c2e9fbca414575d5c080d97f378024a4d131d6e1262112aebaa96eafa3592381 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.