In August 2012, Dorifel was still causing new infections even though antivirus products broadly detected it. Detection did not automatically remove every infected file or stop the malware’s reported spread through email, documents, removable drives and network shares. That is a historical outbreak account—not evidence that the same operation is spreading today.
What was Dorifel malware?
Dorifel, also called XDocCrypt, was the name used for malware reported to be spreading in August 2012. In a report published on August 14, SecurityWeek said the activity had affected at least 30 local governments, universities and businesses in the Netherlands. The article attributed a figure of more than 3,000 systems hit during the preceding week, 90% of them in the Netherlands, to Kaspersky Lab. Those are reported figures from that outbreak, not an audited global total or a current infection count. SecurityWeek’s 2012 report also named Denmark, the Philippines, Germany, the United States and Spain among countries with notable infections.
How did Dorifel spread?
SecurityWeek reported that the malware was initially distributed through targeted email. It could also attach itself to common Microsoft Office formats, including .doc, .docx, .xls and .xlsx, and target mapped network drives and removable storage. A Symantec community report identified Exprez.B as a threat also known as XDocCrypt and Dorifel, and described an earlier version spreading through removable and network drives and infecting executables and Office documents. That is vendor community reporting about the threat family; it does not establish that every variant or infection used every route.
David Jacoby, a Kaspersky Labs researcher quoted by SecurityWeek, described the chain this way: “The malware is initially distributed via email to victims. [It] then downloads another malware, which encrypts documents and executes them on the infected computer. Dorifel also attempts to encrypt files found on network shares.”
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
What did it do, and what is not confirmed?
The 2012 report described web injection, logging of financial information, document encryption and other malicious components, including collections of exploits and additional malware found during investigation. SecurityWeek explicitly characterized the file encryption as not ransomware; the presence of encrypted files alone does not justify calling the incident a ransomware attack.
Investigators noted financial information on the same server and considered whether the activity might be connected to ZeuS or Citadel. Jacoby said they had not identified related ZeuS/Citadel malware and could not confirm a connection. The evidence supports a possible lead, not an attribution.
The report also described a separate risk to worried victims: telephone support scammers were reportedly using Dorifel concerns in the Netherlands to sell purported cleaning or protection. It said there was no indication those scammers were connected to Dorifel’s operators.
Is Dorifel still active?
The cited reporting establishes that Dorifel was spreading in 2012. Microsoft’s threat search later listed multiple Dorifel-named detections, but those labels do not establish that the entries refer to the same malware operation or that the 2012 outbreak is active now. Microsoft’s Dorifel.A page was published on December 6, 2012, and provides detection and cleanup guidance rather than evidence of present-day prevalence. Microsoft’s Trojan:Win32/Dorifel.A description also says technical details are currently unavailable. On the available evidence, present-day activity by the 2012 operation is unresolved.
Recommended Free Tools
What should you do if Microsoft Defender detects Trojan:Win32/Dorifel.A?
Microsoft says Defender Antivirus detects and removes this threat, but warns that an infection can leave remnant files and system changes. Its page recommends updating antimalware definitions and running a full scan, which might help address remnants. It lists possible symptoms such as slow performance, added or modified files, desktop-setting changes, freezing or crashes, and reduced storage space; these symptoms alone do not prove Dorifel is present.
- Update Microsoft Defender’s antimalware definitions.
- Run a full scan, rather than assuming the initial alert accounts for every remnant.
- Follow the current instructions from your security vendor if the detection returns or cleanup is incomplete.
- If this is a managed work or school device—or more than one device may be affected—contact the organization’s IT or incident-response team. Isolate affected systems and review shared drives and removable media as directed by that team.
A single detection or removal message is not proof that a device, shared drive or wider network is clean. For an organization, treat the alert as an incident to assess across potentially connected systems, not simply as a consumer antivirus prompt.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

