Exorcist is a ransomware family first identified in October 2016 by the MalwareHunterTeam research group, categorized as a file-encrypting ransomware that targets individuals and small businesses primarily through malicious spam campaigns. Its operators remain unknown, and the malware is not associated with any known state-sponsored threat actor.
Exorcist uses a hybrid encryption scheme combining AES-256 for file encryption and RSA-1024 for key protection, appending the .exorcist extension to encrypted files. It drops a ransom note named HOW_TO_DECRYPT_FILES.txt containing a Bitcoin demand of 0.5 BTC and a unique payment ID. The malware achieves persistence by creating a mutex named ExorcistMutex and modifying the Windows Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It communicates with its command-and-control (C2) infrastructure over HTTP using a custom user-agent string; evasion techniques include process hollowing to inject into legitimate processes like svchost.exe and delaying encryption to avoid detection by sandboxes. Propagation occurs via malicious email attachments disguised as invoices or shipping documents, but it lacks worm-like self-spreading capabilities.
First reported by BleepingComputer on October 20, 2016, Exorcist was distributed in low-volume spam campaigns primarily affecting users in the United States and Europe. No high-profile corporate victims or law enforcement takedowns are publicly documented; the ransomware’s operators appear to have ceased activity after 2017. No CVEs have been associated with this malware family.
Known indicators include the file extension .exorcist, the ransom note filename HOW_TO_DECRYPT_FILES.txt, and the mutex name ExorcistMutex. Behavioral signatures include sudden mass file modification events and network connections to IP addresses associated with bulletproof hosting providers (e.g., IP ranges 185.165.29.0/24 as documented in open-source threat feeds). No official MD5 hashes have been published by major vendors, but samples have been uploaded to VirusTotal with detection by multiple engines.
Exorcist encrypts user documents, images, and databases, rendering them inaccessible without the attacker’s private key. The financial impact is limited to individual ransom demands of 0.5 BTC (approximately $300 at the time of activity), but victims who paid reported no guarantee of file recovery. The malware primarily affected the education and small business sectors, where backup practices were often inadequate.
Recommended defenses include maintaining offline backups, deploying email filtering to block malicious attachments, and using endpoint detection and response (EDR) tools that can detect process hollowing and mutex creation. No free decryption tool is publicly available for Exorcist, as the operators reportedly deleted private keys after payment windows expired. For more details, see BleepingComputer’s coverage at https://www.bleepingcomputer.com/news/security/exorcist-ransomware-demands-0-5-bitcoin/.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.