Phorpiex Botnet Fuels Ransomware, Sextortion, and Crypto-Theft Attacks
ID: 3096af56-f0a8-5735-9b3a-a9ef957cf0d9
STIX ID: report--3096af56-f0a8-5735-9b3a-a9ef957cf0d9
Feed Name: GBHackers
The report describes the evolution and active use of the Phorpiex (Trik/Twizt) botnet as a multipurpose crime platform: a hybrid C2/P2P architecture distributes ransomware (including LockBit Black and Global-like families), mass sextortion spam, and crypto‑clipping/seed theft. Operators maintain resilience via encrypted payloads, redundant C2 and P2P peer lists, worm-like removable-drive propagation, and targeted delivery (e.g., domain/server checks and geofencing), resulting in large-scale financial theft and extortion worldwide.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
