logo

#StopRansomware: Phobos Ransomware

ID: 48bf0849-2a25-5427-971d-28ccdf40e016

STIX ID: report--48bf0849-2a25-5427-971d-28ccdf40e016

Feed Name: CISA Cybersecurity Advisories

Threat Score
80/100

Date Published: 2024-02-26

Date Updated: 2026-04-19

Author: CISA

...
...

This joint FBI/CISA/MS‑ISAC advisory documents the Phobos ransomware family and affiliate operations, detailing initial access vectors (RDP brute force, phishing), supporting malware (SmokeLoader, Cobalt Strike), reconnaissance and credential theft techniques, persistence and defense‑evasion behaviors, exfiltration methods, sample IOCs (domains, hashes, commands, emails), MITRE ATT&CK mappings, and recommended mitigations and testing actions for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.