CISA & FBI Releases TTPs & IOCs Used by Phobos Ransomware Group
ID: 0b62422e-aed2-54c1-845e-1ef9c497259f
STIX ID: report--0b62422e-aed2-54c1-845e-1ef9c497259f
Feed Name: cybersecurityNews.com
Advisory from FBI, CISA, and MS-ISAC describing Phobos ransomware (a Ransomware-as-a-Service) that has targeted municipal governments, emergency services, education, and public healthcare since 2019; it details access methods (RDP exposure, phishing, brute-force), post-compromise toolsets (Smokeloader, Process Hacker, Universal Virus Sniffer), malicious behaviors (data exfiltration, vssadmin/WMIC shadow copy deletion, full-disk encryption), affiliate extortion practices, IOCs, and recommended mitigations including network segmentation, MFA, application controls, and backup protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
