Xorist

First seen
2016-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-20 15:59:15
Profile updated
2026-07-07 13:40:45

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

Ransomware encrypted files will still have the original non-encrypted header of 0x33 bytes length

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Xorist (yara-rule)

Reports & references

  • support.kaspersky.com — 2911 (report)
  • decrypter.emsisoft.com — Xorist (report)
  • twitter.com — 1006833669447839745 (report)
  • id-ransomware.blogspot.com — Xrtn Ransomware Rsa 1024 Gnu Privacy (report)
  • fortinet.com — Ransomware Roundup New Inlock And Xorist Variants (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Xorist (report)

External references