XData is a ransomware family associated with the wave of disruptive malware activity that heavily affected Ukraine in 2017. It has been repeatedly cited alongside PSCrypt and NotPetya as part of a cluster of ransomware incidents that struck Ukrainian organizations within a short period, and reporting has linked its distribution to compromised update infrastructure associated with the widely used Ukrainian accounting platform M.E.Doc. XData has also been described as using stolen AES-NI code, suggesting code reuse rather than an original ransomware implementation.
The malware’s primary function is file encryption for ransom, placing it in the ransomware category. Its operational significance stems less from novel monetization features than from its role in Ukraine-focused campaigns that appeared timed and targeted in a manner atypical of ordinary indiscriminate cybercrime. Multiple assessments have noted that M.E.Doc-related infrastructure was suspected of delivering XData before later being implicated in the NotPetya supply-chain compromise, indicating that XData may have been propagated through a malicious software update channel affecting business and government users in Ukraine.
XData is most closely associated with Windows enterprise environments because of its linkage to Ukrainian accounting software deployments and broader ransomware activity affecting organizations rather than consumer-only targets. It is frequently referenced in discussions of pseudo-criminal or geopolitically relevant operations aimed at Ukraine, although firm public attribution to a specific actor is not established in the available information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Both XData and the NotPetya ransomware outbreaks used the update servers of M.E.Doc to deliver their ransomware payloads. It is unclear if this recently discovered ransomware reached users via a trojanized update from the same server or a trojanized M.E.Doc app installed from scratch.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of a ransomware family whose victims previously received free decryption keys when operations shut down.
Referenced only as background context about malware previously targeting Ukraine.
A ransomware campaign previously aimed at Ukraine and described here as trying to pass as another family, based on a stolen AES-NI codebase.
Ransomware reportedly suspected to have been distributed earlier through compromised M.E.Doc update servers in Ukraine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.