.xor / .weax Ransomware Decryption: Handling Emerging Variants
Cybersecurity 2026-10-08 CentralComputer Team

.xor / .weax Ransomware Decryption: Handling Emerging Variants

.xor / .weax Ransomware Decryption: Handling Emerging Variants

.xor / .weax Ransomware Decryption: Handling Emerging Variants

Last month, a frozen meat wholesaler in To Kwa Wan switched on their PC to print delivery notes and found every Excel file renamed with a .weax extension — pure gibberish when opened. The accounting department's PCs were hit too; the whole office shared folder was compromised. The owner called us, bewildered: "What is .weax? Google barely has anything on it!"

She was right. .xor and .weax are emerging variants from the last couple of years — sparse online documentation, unfamiliar even to many IT professionals. And that's exactly what makes them dangerous: antivirus may not recognise them, and users have no idea what's happening. Let's dissect these two variants.

Are .xor and .weax related?

Security researchers believe .xor and .weax are likely different "version numbers" from the same ransomware group — like software v1.0 vs v2.0. Evidence:

  • Ransom note format nearly identical, both called README.txt with the same structure, only contact emails differ
  • Consistent extension pattern: originalname.extension, e.g. delivery.xlsx.weax
  • Both use ChaCha20 + RSA hybrid encryption (not traditional AES — notably distinctive)
  • Highly overlapping targets: HK SMEs, no dedicated IT, exposed RDP or old Windows Server

Some cases show .xor, others .weax, sometimes mixed (different batches, different extensions). Handling is essentially the same, so we cover both here.

What makes these new variants nasty?

Compared to "mainstream" ransomware like LockBit or .rox, .xor/.weax have traits particularly painful for SMEs:

  1. They hunt legacy systems: Especially fond of end-of-life Windows Server 2008/2012. Many HK SMEs run decade-old servers they won't replace — right in the crosshairs. The To Kwa Wan case ran Server 2008 R2.
  2. Long dwell time: Instead of encrypting immediately, they lurk for days or even a week, quietly exfiltrating files (preparing double extortion) while your backups capture a false "clean" picture — the backup may already contain the dormant malware.
  3. They kill recovery too: Executes vssadmin delete shadows /all /quiet and bcdedit /set {default} recoveryenabled No, wiping Windows restore points and disabling recovery mode — burning your bridges.
  4. "Affordable" ransoms: Unlike LockBit's six-figure demands, .xor/.weax typically ask 0.05–0.2 BTC (about HK$25,000–100,000). Clever pricing — too cheap isn't worth it, too expensive SMEs can't pay; this range gets the most "gritted teeth" payments.

Response strategy: new variant doesn't mean helpless

The response framework is the same as other ransomware, with a few adjusted details:

Step 1: Confirm it's really .xor/.weax

Upload the ransom note + sample file to ID Ransomware. Being new, the database may not recognise it immediately — don't assume you're safe if it doesn't; treat it as ransomware regardless. Note the contact method: .xor/.weax typically use ProtonMail or Tutanota encrypted email, not dark-web onion links (unlike the big groups).

Step 2: Check for dwell-time contamination

Because of the dwell period, don't restore directly from the latest backup! Verify the backup is clean first:

  • Find backups from at least two weeks before symptoms appeared (if available)
  • Open them in an isolated environment (clean offline PC) and check for suspicious files
  • Look for unfamiliar .exe files or scheduled tasks in the backup

In the To Kwa Wan case, we found a suspicious svchost.exe sitting in the Temp folder of last week's NAS backup — good thing we didn't restore directly, or reinfection would have been instant.

Step 3: Check free decryption possibilities

Honestly, ChaCha20 + RSA has no public break. But:

  • Register for victim notification on No More Ransom — you'll be emailed if a decryptor ever appears
  • Keep all encrypted files + ransom notes; don't delete. You'll need them when a decryptor arrives
  • Some variants have flawed RSA implementations (weak random numbers); security firms occasionally release targeted tools — keep watching

Real case: To Kwa Wan wholesaler's "rustic" rescue

The frozen meat wholesaler looked hopeless: Server 2008, no offline backup, NAS permanently mounted. The entire ordering Excel system and delivery note templates were encrypted.

But there was light:

  1. Paper delivery notes: They printed one copy per delivery for drivers — stacks in the warehouse. A clerk spent two days re-entering a month of delivery notes into Excel.
  2. Suppliers had records: Their upstream frozen meat importers kept complete delivery records — one round of emails recovered all inbound data.
  3. The key: an old laptop: The owner had an old laptop taken home months ago and never used since. It held an older customer list and price list. Not current, but the skeleton was there.

Five days, HK$12,000. The owner said: "I used to complain the paper copies took up space. They saved us." Afterwards we replaced their server (Windows Server 2022), set up daily automated cloud backups, closed RDP in favour of VPN. She now tells everyone: "Having backup isn't enough — you have to back up right."

Preventing new variants: legacy systems are the biggest risk

  • Upgrade Windows Server 2008/2012 immediately: No security updates means the door is wide open. On a budget, consider cloud (Microsoft 365 + SharePoint) instead of maintaining a server.
  • Stop using permanently-mounted NAS as your only backup: Schedule backups, auto-unmount afterwards, or use immutable snapshots.
  • Watch for dwell signs: PC suddenly slow, hard drive light flashing wildly at midnight, unusual outbound connections in firewall logs — possible ransomware lurking.
  • Email gateway filtering: Use email with ATP (advanced threat protection) — Microsoft 365 Business Premium or Google Workspace both filter most phishing.

FAQ

1. Q: Are .xor and .weax the same virus?

A: Very likely different versions from the same group. Ransom note format, encryption method and targets are highly similar. Handle them the same way; no need to split hairs.

2. Q: Google has nothing on .weax. Is it fake?

A: Not fake, just new. Threat intelligence from security vendors typically lags by months. Try ID Ransomware, or get a professional to take a look.

3. Q: Our server is ancient — how much to upgrade?

A: Depends. Going cloud (Microsoft 365) costs about HK$100–150/user/month — ten users is just over HK$10,000/year. A new server with Windows Server licence runs HK$30,000–50,000. We can assess which makes sense.

4. Q: How do I know if malware is lurking?

A: Use Process Explorer for suspicious processes or Autoruns for startup items. But the safest is a professional full check — our on-site assessment starts at HK$800.

Summary

The nastiest thing about .xor/.weax isn't cryptographic sophistication — it's how precisely they target SME legacy systems and weak backups. Response follows the standard ransomware playbook: isolate, identify, don't rush to pay, verify backup cleanliness. Long-term, upgrading legacy systems and proper offline backups are the real cure.

Suspect infection? WhatsApp +852 6558 6806 — we'll help identify the malware free of charge. Learn more in our complete ransomware protection guide.

Found this article helpful?

Feel free to share it with your friends or colleagues.

Call Us