Xorist
- First seen
- 2016-05-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-20 15:59:15
- Profile updated
- 2026-07-07 13:40:45
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality
Context
Ransomware encrypted files will still have the original non-encrypted header of 0x33 bytes length
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Xorist (yara-rule)
Reports & references
- support.kaspersky.com — 2911 (report)
- decrypter.emsisoft.com — Xorist (report)
- twitter.com — 1006833669447839745 (report)
- id-ransomware.blogspot.com — Xrtn Ransomware Rsa 1024 Gnu Privacy (report)
- fortinet.com — Ransomware Roundup New Inlock And Xorist Variants (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Xorist (report)