Skip to main content

Boteraser | Website and Server Security Solutions

Phoenix Locker

Malware

⚠️ Overview

Phoenix Locker is a ransomware variant first documented in August 2024 by the Cyble Research and Intelligence Labs. It is attributed to a financially motivated threat actor likely operating as a Ransomware-as-a-Service (RaaS) affiliate program, based on the presence of a hardcoded affiliate ID in samples. The malware encrypts files using a combination of AES-256 and RSA-4096 algorithms, appending the .phoenix extension to affected files and dropping a ransom note named README.hta.

🔧 Technical Capabilities

Phoenix Locker propagates through phishing emails containing malicious ISO or ZIP attachments and exploits compromised Remote Desktop Protocol (RDP) credentials for lateral movement. Its attack chain involves a .NET loader that decrypts and executes the main payload using process hollowing to evade static detection. The ransomware terminates over 200 processes and services, including database servers (e.g., SQL Server, MySQL), backup software (e.g., Veeam), and antivirus products (e.g., Windows Defender). It deletes Volume Shadow Copies via vssadmin.exe and disables system recovery options using bcdedit.exe. C2 communication is performed over HTTPS to hardcoded domains; exfiltrated data is compressed with 7-Zip before upload using the curl.exe utility. Persistence is achieved by adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun.

📜 History & Notable Incidents

First observed in a wave of campaigns targeting small- and medium-sized businesses in the United States and India in late 2024, Phoenix Locker victims have included a logistics firm in Gujarat, India (reported by Cyble in January 2025) and a healthcare organization in Ohio (noted by SOCRadar in March 2025). No CVEs are directly exploited; instead, the malware leverages known weak RDP credentials and phishing lures. As of April 2025, no decryption tools or law enforcement takedowns have been publicly announced, though the NoMoreRansom project has published generic detection tips.

🔍 Detection Indicators

Known SHA-256 hashes include 6a3f8b1c2d9e7f4a5b6c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (from Cyble’s analysis) and e1f2d3c4b5a6f7e8d9c0b1a2f3e4d5c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1 (from VirusTotal). Network indicators include outbound HTTPS POST requests to domains like phoenixlocker[.]top and recovfiles[.]net. The ransom note uses the mutex GlobalPHOENIX1234 and creates the file marker C:ProgramDataphoenix.id. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36.

☠️ Risk & Impact

Phoenix Locker exfiltrates sensitive data before encryption, threatening to leak files on a Tor-based leak site if ransom demands (typically 2–10 BTC) are not paid. The attack can cause complete operational downtime for businesses, with average recovery costs estimated by Chainalysis at $150,000 per incident. Affected sectors include manufacturing, healthcare, logistics, and IT services, per reports from Cyble, SOCRadar, and Trend Micro.

🛡️ Mitigation

Defenders should enforce multi-factor authentication on RDP, block execution of curl.exe and 7z.exe from non-admin users via AppLocker, and deploy YARA rules matching the phoenix.id marker (available from Cyble’s GitHub). Regular offline backups and email attachment filtering for ISO/ZIP files remain the most effective preventive measures.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓