According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption. During the encryption process, all compromised files are appended with an extension consisting of a ransom string of characters.For example, a file originally named "1.jpg" could appear as something similar to "1.jpg.rnyZoV" following encryption. After this process is complete, Exorcist ransomware changes the desktop wallpaper and drops HTML applications - "[random-string]-decrypt.hta" (e.g. "rnyZoV-decrypt.hta") - into affected folders. These files contain identical ransom messages.
Objectives
Executive Summary
Exorcist is a ransomware group targeting individuals and organizations for financial gain. The actors encrypt victim files and demand payment for decryption keys, using sophisticated tactics to maximize impact and evade detection.
Goals & Targeting
Exorcist seeks organizational gain through targeted ransomware attacks, primarily focusing on individuals and organizations involved in financial transactions or data management. While specific targeting preferences are unclear, the group likely selects victims based on perceived ability to pay ransoms or vulnerability to phishing-based deployments.
Enhanced Description
Exorcist ransomware operates by encrypting compromised systems and appending files with a unique ransom string extension. After encryption, the desktop wallpaper is altered, and HTML-based decryption tools are dropped. These files contain ransom notes demanding payment for access to encrypted data. The group's operations demonstrate a focus on disrupting victims' workflows to coerce timely payments. Exorcist's use of file extension changes and custom decryption tools indicates moderate technical sophistication.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Exorcist campaigns typically involve phishing-based initial access, followed by lateral movement and data encryption. Victims may include businesses or individuals with financial transaction history. The group's operational pattern suggests a focus on quick infections and rapid victim impact to ensure timely payment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence in the data. While Exorcist's core tactics are known, specific aliases, targeted sectors, and campaigns remain unclear. Additional intelligence on exact TTPs and actor locations would improve confidence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics