Exorcist Ransomware

Description Summary

According to PCrisk, Exorcist is a ransomware-type malicious program. Systems infected with this malware experience data encryption and users receive ransom demands for decryption. During the encryption process, all compromised files are appended with an extension consisting of a random string of characters. For example, a file originally named "1.jpg" could appear as something similar to "1.jpg.rnyZoV" following encryption. After this process is complete, Exorcist ransomware changes the desktop wallpaper and drops HTML applications - "[random-string]-decrypt.hta" (e.g. "rnyZoV-decrypt.hta") - into affected folders. These files contain identical ransom messages.

Threat Actor

Operator/affiliate cluster behind the Exorcist leak site. Detailed actor attribution is not available in curated public reporting.

Technical Indicators

Encryption Extension
Not publicly reported
Encryption Algorithm
Not publicly reported
Ransom Note Name
Not publicly reported
Targeted Industries
Cross-sector (per leak-site victim telemetry)
First Seen
Unknown
Last Seen
No public victim disclosures observed
Geographical Location
Global / not publicly profiled

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
Exfiltration x 1 T1567 Exfiltration Over Web Service (leak site)
Initial Access x 2 T1190 Exploit Public-Facing Application
T1078 Valid Accounts