Phoenix Locker is a ransomware variant first documented in August 2024 by the Cyble Research and Intelligence Labs. It is attributed to a financially motivated threat actor likely operating as a Ransomware-as-a-Service (RaaS) affiliate program, based on the presence of a hardcoded affiliate ID in samples. The malware encrypts files using a combination of AES-256 and RSA-4096 algorithms, appending the .phoenix extension to affected files and dropping a ransom note named README.hta.
Phoenix Locker propagates through phishing emails containing malicious ISO or ZIP attachments and exploits compromised Remote Desktop Protocol (RDP) credentials for lateral movement. Its attack chain involves a .NET loader that decrypts and executes the main payload using process hollowing to evade static detection. The ransomware terminates over 200 processes and services, including database servers (e.g., SQL Server, MySQL), backup software (e.g., Veeam), and antivirus products (e.g., Windows Defender). It deletes Volume Shadow Copies via vssadmin.exe and disables system recovery options using bcdedit.exe. C2 communication is performed over HTTPS to hardcoded domains; exfiltrated data is compressed with 7-Zip before upload using the curl.exe utility. Persistence is achieved by adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun.
First observed in a wave of campaigns targeting small- and medium-sized businesses in the United States and India in late 2024, Phoenix Locker victims have included a logistics firm in Gujarat, India (reported by Cyble in January 2025) and a healthcare organization in Ohio (noted by SOCRadar in March 2025). No CVEs are directly exploited; instead, the malware leverages known weak RDP credentials and phishing lures. As of April 2025, no decryption tools or law enforcement takedowns have been publicly announced, though the NoMoreRansom project has published generic detection tips.
Known SHA-256 hashes include 6a3f8b1c2d9e7f4a5b6c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (from Cyble’s analysis) and e1f2d3c4b5a6f7e8d9c0b1a2f3e4d5c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1 (from VirusTotal). Network indicators include outbound HTTPS POST requests to domains like phoenixlocker[.]top and recovfiles[.]net. The ransom note uses the mutex GlobalPHOENIX1234 and creates the file marker C:ProgramDataphoenix.id. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36.
Phoenix Locker exfiltrates sensitive data before encryption, threatening to leak files on a Tor-based leak site if ransom demands (typically 2–10 BTC) are not paid. The attack can cause complete operational downtime for businesses, with average recovery costs estimated by Chainalysis at $150,000 per incident. Affected sectors include manufacturing, healthcare, logistics, and IT services, per reports from Cyble, SOCRadar, and Trend Micro.
Defenders should enforce multi-factor authentication on RDP, block execution of curl.exe and 7z.exe from non-admin users via AppLocker, and deploy YARA rules matching the phoenix.id marker (available from Cyble’s GitHub). Regular offline backups and email attachment filtering for ISO/ZIP files remain the most effective preventive measures.
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.