Xorist

Threat Actor updated a month ago (2024-11-29T13:59:15.000Z)
Download STIX
Preview STIX
**Executive Summary: Threat Actor Xorist** Xorist is a notable threat actor associated with ransomware attacks, particularly known for its development and distribution of the Xorist ransomware variant. Initially identified in 2020, Xorist has evolved through multiple iterations, often leveraging sophisticated multi-stage loaders to infiltrate victim systems. This group is suspected to have ties to a Russian-speaking cybercriminal organization known as "huis," which primarily conducts spam raids on platforms like Telegram. The early versions of Xorist encrypted files using the .huis_bn extension and established persistence by modifying file extension associations. The Xorist ransomware downloader, identified as "1.exe," and its decrypting tool have been pivotal in addressing the damage caused by various ransomware strains, including Apocalypse and BadBlock. Security researchers have noted that tools developed by companies such as Trend Micro and Emsisoft have proven effective in restoring access to files affected by Xorist and other major ransomware. As the ransomware landscape evolves, Xorist has introduced new variants that append extensions like .WoXoTo and .RSA-4096, accompanied by ransom notes instructing victims on how to recover their files. Recent investigations revealed that Xorist's infrastructure included downloading additional ransomware samples, notably Chaos, indicating a broader strategy to maximize impact on victims. With each new variant, the threat posed by Xorist continues to grow, necessitating ongoing vigilance from cybersecurity professionals. The emergence of new variants and the group's adaptive tactics underline the importance of robust cybersecurity measures and timely updates to defense mechanisms against evolving ransomware threats.
Description last updated: 2024-10-01T14:15:31.882Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Mortalkombat is a possible alias for Xorist. MortalKombat is a new ransomware family that was discovered by Talos earlier this year. It was generated by the leaked Xorist ransomware builder, a type of malware that has been in existence since 2016. MortalKombat has been used by an unidentified threat actor since December 2022 to target individu
4
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Xorist Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more