Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors exorcist

Description

According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption. During the encryption process, all compromised files are appended with an extension consisting of a ransom string of characters.For example, a file originally named "1.jpg" could appear as something similar to "1.jpg.rnyZoV" following encryption. After this process is complete, Exorcist ransomware changes the desktop wallpaper and drops HTML applications - "[random-string]-decrypt.hta" (e.g. "rnyZoV-decrypt.hta") - into affected folders. These files contain identical ransom messages.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Exorcist is a ransomware group targeting individuals and organizations for financial gain. The actors encrypt victim files and demand payment for decryption keys, using sophisticated tactics to maximize impact and evade detection.

Goals & Targeting

Exorcist seeks organizational gain through targeted ransomware attacks, primarily focusing on individuals and organizations involved in financial transactions or data management. While specific targeting preferences are unclear, the group likely selects victims based on perceived ability to pay ransoms or vulnerability to phishing-based deployments.

Enhanced Description

Exorcist ransomware operates by encrypting compromised systems and appending files with a unique ransom string extension. After encryption, the desktop wallpaper is altered, and HTML-based decryption tools are dropped. These files contain ransom notes demanding payment for access to encrypted data. The group's operations demonstrate a focus on disrupting victims' workflows to coerce timely payments. Exorcist's use of file extension changes and custom decryption tools indicates moderate technical sophistication.

Key Capabilities

  • Ransomware deployment with file encryption
  • Modifying desktop wallpaper for intimidation
  • Dropping HTML decryption tools with ransom notes
  • Communicating via encrypted channels for C2

MITRE ATT&CK Tactics

Initial Access
Data Exfiltration
Persistence
Impact

ATT&CK Techniques

T1003.001
T1485
T1048
T1071

Software / Tooling

Generic ransomware
Custom encryption tools
Phishing emails with macro payloads

Campaigns & Victims

Exorcist campaigns typically involve phishing-based initial access, followed by lateral movement and data encryption. Victims may include businesses or individuals with financial transaction history. The group's operational pattern suggests a focus on quick infections and rapid victim impact to ensure timely payment.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents
  • Encrypted C2 communication channels
  • Files with appended .rnyZoV-like extensions
  • Dropped HTML decryption files

Recommended Actions

  • Implement strong email filtering to block phishing attempts
  • Monitor for file extension changes indicative of encryption
  • Educate users on recognizing suspicious emails and attachments
  • Regularly back up critical data offline
  • Segment networks to limit lateral movement potential

Suggested Tags

Ransomware
Financial Motivation
File Encryption
Moderate Sophistication

Confidence Assessment

Medium confidence in the data. While Exorcist's core tactics are known, specific aliases, targeted sectors, and campaigns remain unclear. Additional intelligence on exact TTPs and actor locations would improve confidence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial Motivation
File Encryption
Moderate Sophistication

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.