Xorist is a long-running Windows ransomware family known for encrypting victim files and demanding payment for decryption. It has been widely tracked under Win32 ransomware naming conventions and has appeared in multiple campaigns and variants over time. Xorist is notable both as an established family in its own right and as a code lineage associated with later ransomware operations, including assessments linking MortalKombat to the Xorist family based on code and implementation similarities.
Xorist targets Windows systems and is associated with typical ransomware behaviors including file encryption, ransom-note creation, and user-impacting system changes. Reporting tied to Xorist-family activity indicates persistence mechanisms through autorun configuration, and some variants or related descendants have altered the desktop environment and impaired normal system usability after encryption. Xorist has also been referenced in connection with email-borne ransomware delivery, indicating that phishing or malspam can serve as an access vector in at least some campaigns.
The family has remained sufficiently prevalent and recognizable to be included in major ransomware tracking and recovery efforts, and publicly available decryptors exist for at least some Xorist variants. Xorist has also surfaced in comparative analysis of other malware, including overlap in ransom-note contact details seen in unrelated destructive malware masquerading as ransomware, though such overlap alone does not establish operational identity. Overall, Xorist is best understood as a well-known Windows ransomware family with multiple variants, recurring criminal use, and a history of both direct ransomware deployment and code-family reuse in later campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family targeted by Emsisoft's decryption tool.
Ransomware family named as a source of leaked builders/code for new variants.
Longstanding ransomware family, active since 2010, with multiple customizable variants generated via a leaked builder. In this report it is discussed as the family Talos believes MortalKombat belongs to.
Ransomware family mentioned because ransom-note email overlap was found between CryWiper and samples from this family.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.