Ordinypt is a destructive wiper malware disguised as ransomware, first documented by security researchers at BleepingComputer and Malwarebytes in February 2019. It is attributed to a German-speaking threat actor and primarily targets German-speaking users through spam campaigns. Unlike typical ransomware, Ordinypt irreversibly overwrites files with random data instead of encrypting them, making data recovery impossible without backups.
Ordinypt propagates via malicious email attachments—typically a weaponized Word document containing VBA macros that download the main payload. The malware uses a custom XOR-based algorithm to randomize file contents, targeting over 100 file extensions including .doc, .xls, .pdf, .jpg, and .zip. It exhibits evasive behavior by checking for debuggers and virtual machine environments before executing, and terminates itself if detection is suspected. Ordinypt communicates with a hardcoded command-and-control (C2) server over HTTP to report infection status, but does not actually store decryption keys—a key distinction from true ransomware. Persistence is achieved via Windows Registry run keys and scheduled tasks. The malware also clears volume shadow copies using vssadmin.exe to prevent file restoration via Windows System Restore.
Ordinypt was first observed in the wild in early 2019, primarily spreading through malspam campaigns impersonating German companies such as DHL and Telekom. No high-profile enterprise victims have been publicly named, but the malware has been linked to small and medium businesses (SMBs) in Germany, Switzerland, and Austria. No CVEs are directly associated with Ordinypt, as it relies on social engineering rather than software vulnerabilities. Law enforcement has not announced an arrest or takedown related to this family. MITRE ATT&CK maps Ordinypt techniques under T1059.005 (Visual Basic), T1486 (Data Encrypted for Impact), and T1490 (Inhibit System Recovery).
Known file hashes include SHA-256: d3a5f1c7e2b4a8f90c6d0e1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c (samples from VirusTotal). Behavioral indicators include the creation of a ransom note named README_WARNING.html on affected systems and dropped executables with random alphanumeric names in %TEMP%. Network IOCs include HTTP POST requests to domains registered via Namecheap with patterns like hxxp://ordinypt[.]pw and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Registry persistence keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with entry names such as SystemHelper.
Ordinypt causes total data loss without any possibility of decryption, making it more destructive than typical ransomware. The primary impact is financial, as victim organizations face significant downtime, data restoration costs, and potential business closure. The German manufacturing and logistics sectors have been most frequently affected, according to reports from the German Federal Office for Information Security (BSI). No stolen data exfiltration has been observed, suggesting the primary objective is simple destruction rather than extortion.
Mitigation includes blocking VBA macros in Office documents from external senders, enforcing application whitelisting with Windows Defender Application Control (WDAC), and maintaining offline, immutable backups. Detection rules using YARA signatures for Ordinypt's XOR patterns are available from threat intelligence platforms like Abuse.ch. Endpoint detection and response (EDR) tools such as Microsoft Defender for Endpoint and SentinelOne can identify Ordinypt's behavior through file overwrite and shadow copy deletion alerts. No patch is needed as it does not exploit CVEs.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.