Exorcist Ransomware

Exorcist ransomware has surfaced on Russian dark web forums looking for affiliates willing to carry out attacks with its malware, the group offers 70% of the ransom to its affiliates.

This tactic is called RaaS (Ransomware as a Service) which is the outsourcing of attacks, is used to expand the group’s influence. Affiliates have some freedom to carry out attacks, one of the few restrictions being attacks on countries that are members of the former Soviet Union.

Several ransomware groups treat these countries with a certain amount of fear, the best explanation is that these groups control their attacks from these countries, and do not want the attention of the authorities, so they mainly target Western countries.

Exorcist uses AES 256 + RSA 4096 encryption, this combination of algorithms increases the reliability of the encryption, making it virtually impossible to break without the decryption key that the group keeps on a remote server.

All files affected by the ransomware are given an extension with a sequence of random characters, this extension is the same for all files, and the ransom note also carries in its name the random characters.

On the ransom note are all the necessary information for the victim to contact the criminals and pay the ransom, even though the group does not give any guarantees whether they will actually release the decryption key after payment.

Recover files encrypted by Exorcist ransomware

Digital Recovery specialises in the recovery of data encrypted by ransomware, without the need for the decryption key. We have over 23 years of experience in the data recovery market.

We act in the most complex scenarios of data loss by ransomware attacks, we act with high precision and agility.

Our solutions are customised to best suit the real needs of each of our clients. All of them were developed based on the General Data Protection Regulation (GDPR).

We do not negotiate with hackers, we keep all information about the process confidential, we guarantee this through the confidentiality agreement (NDA).

We develop technologies that can be applied remotely, our solutions can be executed in companies all over the world.

Contact us and start data recovery now.

We are
always online

Please fill out the form, or select your preferred contact method. We will contact you to start recovering your files.

Latest insights from our experts

Recover BlogXX Ransomware

Ransomware BlogXX

The BlogXX ransomware group recently emerged with the theft of patient data from Mediabank, an Australian health insurer, on October 12. According to authorities, the


Pozq ransomware

Pozq ransomware was recently discovered after a sample submission on VirusTotal. After some analysis, evidence was highlighted that Pozq may have a relationship with the

Ransomware buybackdate

Buybackdate Ransomware

Buybackdate ransomware is the name of the newest extension that was discovered by cybersecurity researchers through VirusTotal. According to the experts, buybackdate belongs to the


Through unique technologies Digital Recovery can bring back encrypted data on any storage device, offering remote solutions anywhere in the world.