Threat reportMalwareTL-2026-0764

EvilNominatus Ransomware — BAT-delivered .NET (MSIL) Filecoder attributed to an Iranian developer

lowACTIVE

EvilNominatus Ransomware (TL-2026-0764), also tracked as NominatusStrike, is a low-severity malware campaign, first published 2022-04-07. It carries a reported Iran nexus and is not formally attributed, affects Microsoft Windows, maps to 12 MITRE ATT&CK techniques (T1027, T1059, T1083), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
LOWAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0764

Threat ID
TL-2026-0764
Also known as
NominatusStrike, Ransom.NominatusStrike, VirusNominatus, EvilNominatusCrypto
Severity
LOW
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Nation-state nexus
Iran
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
20

Malware and tooling in EvilNominatus Ransomware

Malware and tooling: EvilNominatus, NominatusStrike, Ransom.EvilNominatus.C, Encoded BAT loader (~650KB)

How EvilNominatus Ransomware works

EvilNominatus (aka NominatusStrike / VirusNominatus) is a low-sophistication .NET/MSIL ransomware family first exposed at the end of 2021 and analyzed by ClearSky in April 2022. It is delivered via heavily obfuscated, large (~650KB) encoded BAT scripts with near-zero antivirus detection (one sample flagged by only two engines, a later sample by none). ClearSky attributes the tooling to a young Iranian developer who publicly bragged about it on Twitter and Discord; overall risk was assessed LOW with no known victims at the time of publication.

EvilNominatus is a self-authored ransomware family rather than a professional ransomware-as-a-service operation. ClearSky's research ('Exposing the Iranian EvilNominatus Ransomware', 7 April 2022) began with a malicious BAT file uploaded to VirusTotal from Iran. The BAT — roughly 650KB in its encoded form — acts as a loader/dropper: per ClearSky it can download additional malicious files, delete Volume Shadow Copies, encrypt files, cancel/disable the Windows registry editor (regedit), disable Task Manager (taskmgr), and carry out multiple additional capabilities. The original BAT was detected by only two AV engines on VirusTotal; a second, characteristically similar BAT discovered later was detected by no engines at all, which is the primary reason ClearSky published despite assessing the family as low risk. Files generated by, or contacted by, the BATs were detected by multiple AV engines.

The payload is a .NET / MSIL executable (ESET classifies it as MSIL/Filecoder.EvilNominatus; a public sample carries the internal name VirusNominatus.exe, File/Product Version 1.0.8136.34981, Product Name 'VirusNominatus', Legal Copyright 'Copyright 2022'). On execution the ransomware enumerates user files and encrypts them, appending the extension '-Locked' to each affected file (e.g. '1.jpg' -> '1.jpg-Locked'); because files can be processed more than once, multiple '-Locked' suffixes may stack ('file.jpg-Locked-Locked'). Rather than dropping a text ransom note, it presents a pop-up window. The note text observed reads: 'Ransom.EvilNominatus.C / CryptoVirus Detected! Ransom.NominatusStrike / your files has been encrypted if you enter the wrong key 3 times we will make you see dark side ... Contact Bkhtyaryrwzbh@gmail.com / we deleted your backups, we disabled taskmgr, regedit and more ... Code: [GO AWAY!!]'. The note threatens destructive action after three incorrect key entries, claims backups were deleted (consistent with the observed shadow-copy deletion), and provides the contact email bkhtyaryrwzbh@gmail.com. A static removal/decryption code string ('7HJA817273-zXhsgSUS89-XX98UYHBVZ-9182TEFGIJK') has been documented by removal-guide sources.

ClearSky's report additionally documents the developer's email address and their Discord and Twitter usernames, attributing the tool to a young Iranian author who bragged about its development on Twitter. No victims were known at publication and no CVE is involved; the family's significance is its distinctive BAT-based operation and its very low AV detection rate at the time. Defenders should treat the family as a representative example of low-cost, individually-developed ransomware that leans on script obfuscation and standard recovery-inhibition (shadow-copy deletion, disabling defensive admin tools) rather than novel technique.

MITRE ATT&CK techniques used in TL-2026-0764

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Discovery

T1083 File and Directory Discovery

Command and Control

T1105 Ingress Tool Transfer

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Initial Access

T1566 Phishing

Affected products and versions in EvilNominatus Ransomware

  • Microsoft — Windows
    Vulnerable versions: Windows endpoints capable of running .NET/MSIL executables and cmd.exe BAT scripts

Remediation for EvilNominatus Ransomware

Immediate actions

  • Isolate affected hosts and identify the scope of files renamed with the '-Locked' extension
  • Block execution of unsigned/obfuscated .BAT scripts from user-writable paths via application control / AppLocker / WDAC
  • Restore impacted files from offline, immutable backups (decryption is not publicly available)
  • Hunt for and block the contact indicator bkhtyaryrwzbh@gmail.com in mail and DLP controls

Workarounds

  • Disable or constrain cmd.exe/wscript execution for non-admin users where feasible
  • Protect Task Manager and Registry Editor policy keys and alert on changes to DisableTaskMgr / DisableRegistryTools

Longer-term hardening

  • Deploy EDR with behavioral detection for mass file modification, shadow-copy deletion, and tampering with DisableTaskMgr/DisableRegistryTools
  • Maintain offline/immutable, regularly tested backups so shadow-copy deletion does not eliminate recovery options
  • Enforce script-block logging (PowerShell) and command-line process auditing to surface obfuscated BAT loaders
  • Restrict the ability of standard users to modify Volume Shadow Copies (vssadmin/wmic/wbadmin)

Timeline of EvilNominatus Ransomware

  • The Iranian developer publicly bragged about authoring the ransomware on Twitter and Discord, where ClearSky documented the developer's email, Twitter and Discord usernames.
  • EvilNominatus ransomware first exposed at the end of 2021; the family is developed and self-promoted by a young Iranian developer.
  • A malicious ~650KB encoded BAT loader associated with EvilNominatus was uploaded to VirusTotal from Iran, the artifact that began ClearSky's investigation.
  • ClearSky assessed the family's general level of risk as low, with no known victims at the time of publication and no CVE involved.
  • ClearSky published 'Exposing the Iranian EvilNominatus Ransomware' (7 April 2022) documenting the BAT-based operation, IOCs, and attribution.
  • The .NET/MSIL payload (internal name VirusNominatus.exe, File/Product Version 1.0.8136.34981, Product Name 'VirusNominatus', Copyright 2022) encrypts files, appends '-Locked', and shows a pop-up ransom note instead of a text file.
  • A second BAT sharing characteristics with the first was discovered and detected by no antivirus engines at all, the primary reason ClearSky decided to publish.
  • The first encoded BAT was detected by only two antivirus engines on VirusTotal; it can download additional files, delete Volume Shadow Copies, encrypt files, and disable regedit and taskmgr.
  • Multiple AV vendors added detections for later samples, e.g. ESET MSIL/Filecoder.EvilNominatus.E, Kaspersky HEUR:Trojan.MSIL.DelShad.gen, Microsoft Trojan:Win32/Wacatac.B!ml, Avast Win32:TrojanX-gen, Combo Cleaner IL:Trojan.MSILZilla.12204.

Sources cited for EvilNominatus Ransomware

Detection coverage for TL-2026-0764

As of 2022-04-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0764 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats