logo

CISA & FBI Releases TTPs & IOCs Used by Phobos Ransomware Group

ID: 0b62422e-aed2-54c1-845e-1ef9c497259f

STIX ID: report--0b62422e-aed2-54c1-845e-1ef9c497259f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2024-03-05

Date Updated: 2026-04-21

Author: Balaji N

...
...

Advisory from FBI, CISA, and MS-ISAC describing Phobos ransomware (a Ransomware-as-a-Service) that has targeted municipal governments, emergency services, education, and public healthcare since 2019; it details access methods (RDP exposure, phishing, brute-force), post-compromise toolsets (Smokeloader, Process Hacker, Universal Virus Sniffer), malicious behaviors (data exfiltration, vssadmin/WMIC shadow copy deletion, full-disk encryption), affiliate extortion practices, IOCs, and recommended mitigations including network segmentation, MFA, application controls, and backup protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.