logo

Hackers Use Phorpiex Botnet to Spread Ransomware, Sextortion, and Crypto-Clipping Malware

ID: 57a3abcf-f7ed-5c8d-b89b-b8deb41d8e39

STIX ID: report--57a3abcf-f7ed-5c8d-b89b-b8deb41d8e39

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2026-04-03

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

Phorpiex (aka Trik, Twizt variant) is an active, high-scale botnet running a hybrid P2P and C2 infrastructure that infects hundreds of thousands of devices to simultaneously deliver ransomware (including LockBit-like and Global-family strains), send large-scale sextortion spam campaigns targeting millions of addresses, and perform real-time cryptocurrency wallet hijacking; the report details persistence and evasion techniques, geographic impact, and recommends blocking known C2s, monitoring autorun registry changes, restricting USB access, disabling UPnP, patching systems, and deploying layered email filtering, with IOCs published on Malware Bazaar.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.