# EvilNominatus Ransomware — BAT-delivered .NET (MSIL) Filecoder attributed to an Iranian developer

> EvilNominatus (aka NominatusStrike / VirusNominatus) is a low-sophistication .NET/MSIL ransomware family first exposed at the end of 2021 and analyzed by ClearSky in April 2022. It is delivered via heavily obfuscated, large (~650KB) encoded BAT scripts with near-zero antivirus detection (one sample flagged by only two engines, a later sample by none). ClearSky attributes the tooling to a young Iranian developer who publicly bragged about it on Twitter and Discord; overall risk was assessed LOW with no known victims at the time of publication.

- **Published:** 2022-04-07T00:00:00Z
- **Last reviewed:** 2022-04-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0764
- **ID:** TL-2026-0764
- **Severity:** LOW
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

EvilNominatus is a self-authored ransomware family rather than a professional ransomware-as-a-service operation. ClearSky's research ('Exposing the Iranian EvilNominatus Ransomware', 7 April 2022) began with a malicious BAT file uploaded to VirusTotal from Iran. The BAT — roughly 650KB in its encoded form — acts as a loader/dropper: per ClearSky it can download additional malicious files, delete Volume Shadow Copies, encrypt files, cancel/disable the Windows registry editor (regedit), disable Task Manager (taskmgr), and carry out multiple additional capabilities. The original BAT was detected by only two AV engines on VirusTotal; a second, characteristically similar BAT discovered later was detected by no engines at all, which is the primary reason ClearSky published despite assessing the family as low risk. Files generated by, or contacted by, the BATs were detected by multiple AV engines.

The payload is a .NET / MSIL executable (ESET classifies it as MSIL/Filecoder.EvilNominatus; a public sample carries the internal name VirusNominatus.exe, File/Product Version 1.0.8136.34981, Product Name 'VirusNominatus', Legal Copyright 'Copyright 2022'). On execution the ransomware enumerates user files and encrypts them, appending the extension '-Locked' to each affected file (e.g. '1.jpg' -> '1.jpg-Locked'); because files can be processed more than once, multiple '-Locked' suffixes may stack ('file.jpg-Locked-Locked'). Rather than dropping a text ransom note, it presents a pop-up window. The note text observed reads: 'Ransom.EvilNominatus.C / CryptoVirus Detected! Ransom.NominatusStrike / your files has been encrypted if you enter the wrong key 3 times we will make you see dark side ... Contact Bkhtyaryrwzbh@gmail.com / we deleted your backups, we disabled taskmgr, regedit and more ... Code: [GO AWAY!!]'. The note threatens destructive action after three incorrect key entries, claims backups were deleted (consistent with the observed shadow-copy deletion), and provides the contact email bkhtyaryrwzbh@gmail.com. A static removal/decryption code string ('7HJA817273-zXhsgSUS89-XX98UYHBVZ-9182TEFGIJK') has been documented by removal-guide sources.

ClearSky's report additionally documents the developer's email address and their Discord and Twitter usernames, attributing the tool to a young Iranian author who bragged about its development on Twitter. No victims were known at publication and no CVE is involved; the family's significance is its distinctive BAT-based operation and its very low AV detection rate at the time. Defenders should treat the family as a representative example of low-cost, individually-developed ransomware that leans on script obfuscation and standard recovery-inhibition (shadow-copy deletion, disabling defensive admin tools) rather than novel technique.

## MITRE ATT&CK

- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1112 Modify Registry
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1485 Data Destruction

## Sources

- [Exposing the Iranian EvilNominatus Ransomware (ClearSky, full report PDF)](https://www.clearskysec.com/wp-content/uploads/2022/04/EvilNominatus_Ransomware_7.4.22.pdf)
- [EvilNominatus Ransomware — ClearSky Cyber Security](https://www.clearskysec.com/evilnominatus-ransomware/)
- [EvilNominatus Ransomware - Decryption, removal, and lost files recovery](https://www.pcrisk.com/removal-guides/23113-evilnominatus-ransomware)
- [MSIL/Filecoder.EvilNominatus.A — How To Fix Guide](https://howtofix.guide/msil-filecoder-evilnominatus-a/)
- [Trojan.EvilNominatus.MSIL — How To Fix Guide (VirusNominatus.exe metadata)](https://howtofix.guide/trojan-evilnominatus-msil/)
- [VirusTotal — EvilNominatus-associated sample](https://www.virustotal.com/gui/file/dca4ecd769253d3b4a165a5bbadbb7ce48aa89451b46eb05185f922e931da156)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0764
