Ordinypt, also known as GermanWiper and initially identified as HSDFSDCrypt, is a destructive Windows malware family that masquerades as ransomware but functions as a wiper. It was observed targeting organizations in Germany, particularly through German-language job-application lures aimed at human resources personnel. The malware was distributed via phishing emails impersonating applicants and used disguised executables within archive attachments to induce execution.
Once launched, Ordinypt searches for victim files in a ransomware-like manner but does not perform recoverable encryption. Instead, it overwrites file contents with random data, creates pseudo-encrypted replacement files with randomized names, and deletes the original files. Public reporting has also described variants or analyses in which destroyed files were overwritten or truncated, reinforcing that the malware’s purpose is irreversible data destruction rather than monetization. It drops ransom notes claiming AES-based encryption and demanding Bitcoin payment, but the payment workflow is not operationally credible: the note lacks a practical victim identification and contact mechanism, and wallet selection behavior indicates deception rather than a viable recovery process.
Ordinypt is best understood as a wiper disguised as ransomware, comparable in concept to other destructive operations that use ransom demands as cover for sabotage or disruption. Its tradecraft indicates intent to maximize operational impact on targeted German organizations rather than to support genuine extortion. The campaign is notable for combining socially engineered initial access with overtly destructive post-execution behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Ordinypt is actually a wiper and not ransomware because it does not bother encrypting anything, but just replaces files with random data.
encrypting a file and destroying the key is essentially equivalent to destroying the file... This was the case with NotPetya, which did encrypt files properly.
It also destroyed recovery options, such as the Windows shadow copy.
They may damage data instead of encrypting it or make the retrieval of the key(s) impossible, e.g., Ordinypt. Creating a wiper that poses as file or disc encrypter may also be done on purpose if the actual goal is to damage a business and threat actors want to hide their intent.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fake ransomware-style wiper that altered files, added random extensions, destroyed recovery options, and displayed a ransom note, but actually filled files with zero bytes and truncated them, making recovery impossible.
A ransomware example used to illustrate destructive behavior where data may be damaged instead of recoverably encrypted.
Ordinypt is a wiper disguised as ransomware. It is delivered via German-language job application phishing emails, executes from disguised EXE attachments, searches for files, replaces their contents with random data, deletes the originals, renames the resulting garbage files with random 14-character alphanumeric names, and drops ransom notes despite offering no real recovery path.
The Anatomy of Wiper Malware, Part 1: Common Techniques ... Ordinypt ...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.