Phorpiex’s New P2P Upgrade Makes This 15-Year-Old Botnet Unstoppable
ID: 2f82dce8-f40e-57c8-a7e2-81e13dfef087
STIX ID: report--2f82dce8-f40e-57c8-a7e2-81e13dfef087
Feed Name: securityonline.info
Bitsight Threat Research finds that the long-lived Phorpiex (Trik) botnet’s new 'Twizt' variant has evolved from spam into a resilient, multi-purpose malware platform using a hybrid HTTP and P2P (TCP/UDP) C2 architecture; observed behaviors include deploying XMRig cryptominers, running LFI vulnerability scanners, maintaining global telemetry of infections, and protecting payloads with a custom 256-byte RSA-encrypted header, prompting recommendations for behavior-based detection and strong network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
