Xorist

Threat Actor updated 4 months ago (2024-05-04T16:58:13.910Z)
Download STIX
Preview STIX
Xorist is a significant threat actor in the cybersecurity landscape, known for its malicious activities involving ransomware attacks. The Xorist ransomware first emerged in 2010 and primarily targets Windows systems. It operates under the Ransomware-as-a-Service (RaaS) model with a builder called "Encoder Builder v.24" available on underground forums, facilitating the creation of new variants. The ransomware has been notably associated with file extensions like .WoXoTo or .RSA-4096 and drops a ransom note named "HOW TO DECRYPT FILES.txt". Decrypting tools have been developed to counteract Xorist's impact, such as those provided by Trend Micro and Emsisoft, which have proven effective against major ransomwares including Apocalypse, Xorist, Stampado, and BadBlock. In early 2024, cybersecurity firm Talos discovered a new ransomware family called MortalKombat, generated by the leaked Xorist ransomware builder. Despite being a new entrant, MortalKombat shares striking similarities with the Xorist ransomware family, evidenced by commonalities in code, class name, and registry key strings. This led experts to assess with high confidence that MortalKombat belongs to the Xorist ransomware family. MortalKombat spreads through phishing emails and targets exposed Remote Desktop Protocol (RDP) instances, further extending the reach and potential impact of the Xorist threat actor. The ongoing evolution and adaptation of the Xorist ransomware pose a considerable threat to cybersecurity. The emergence of new variants and the development of derivative ransomware families like MortalKombat underscore the persistent risk associated with this threat actor. As such, it remains crucial for organizations to maintain robust security measures, including regular system updates, backups, and user education on phishing scams. Furthermore, the continued development and application of decryption tools will be vital in mitigating the effects of Xorist-related ransomware attacks.
Description last updated: 2024-05-04T16:44:02.563Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Mortalkombat
4
MortalKombat is a new ransomware family that was discovered by Talos earlier this year. It was generated by the leaked Xorist ransomware builder, a type of malware that has been in existence since 2016. MortalKombat has been used by an unidentified threat actor since December 2022 to target individu
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Xorist Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
6 months ago
The Week in Ransomware - March 1st 2024 - Healthcare under siege
CERT-EU
8 months ago
The Week in Ransomware - January 5th 2024 - Secret decryptors
CERT-EU
2 years ago
Fatality: 'Mortal Kombat' Ransomware Targets Windows Systems in US | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware - National Cyber Security
Bitdefender
2 years ago
Bitdefender Releases Decryptor for MortalKombat Ransomware
CERT-EU
2 years ago
Meet the new Mortal Kombat Ransomware - Cybersecurity Insiders
Unit42
a year ago
Ransomware Delivery URLs: Top Campaigns and Trends
CERT-EU
a year ago
Code leaks are causing an influx of new ransomware actors
Securityaffairs
2 years ago
Bitdefender released free decryptor for MortalKombat Ransomware
CERT-EU
a year ago
200+ Free Ransomware Decryption Tools You Need [2022 List]
Malwarebytes
2 years ago
Mortal Kombat ransomware forms tag team with crypto-stealing malware
CERT-EU
a year ago
Tsetso Mihailov
CERT-EU
2 years ago
Cryptocurrency users in the US hit by ransomware and Clipper malware | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware - National Cyber Security
InfoSecurity-magazine
2 years ago
Crypto-Stealing Campaign Deploys MortalKombat Ransomware
CERT-EU
a year ago
The Week in Ransomware - September 29th 2023 - Dark Angels