Phorpiex

Malware

⚠️ Overview

Phorpiex (also tracked as Trik) is a modular botnet first identified in 2016 by security researchers at Trend Micro, primarily used to distribute ransomware, sextortion campaigns, and information stealers. It is operated by an unknown threat actor and belongs to the category of botnet malware that leverages spam‑driven infection chains and a peer‑to‑peer (P2P) command‑and‑control (C2) infrastructure based on the Kademlia Distributed Hash Table (DHT) protocol.

🔧 Technical Capabilities

Phorpiex propagates via malicious email attachments, typically disguised as invoices, shipping notifications, or legal documents, using weaponized macros or exploit documents (e.g., CVE‑2017‑11882 for Equation Editor). Once executed, it establishes persistence by adding a registry Run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value like svchost.exe) and injects its payload into legitimate processes via process hollowing. The botnet communicates with its P2P network using UDP on random high ports (e.g., 1024‑65535), employing DHT lookups to locate other peers and retrieve encrypted commands. Evasion techniques include anti‑debugging checks (IsDebuggerPresent), anti‑VM heuristics (checking for disk sizes, MAC addresses), and dynamic code obfuscation. It can download and execute secondary payloads (e.g., GandCrab, Avaddon ransomware) and exfiltrate system information including email addresses, browser credentials, and cryptocurrency wallet files. The botnet also features a built‑in spam module that uses stolen email credentials to resend phishing messages, creating a self‑propagating cycle.

📜 History & Notable Incidents

Phorpiex first appeared in 2016 and gained prominence in 2018–2019 when it was used to distribute the GandCrab ransomware in massive spam campaigns, infecting thousands of victims worldwide. In 2020, it shifted to distributing Avaddon ransomware, contributing to a surge in cryptocurrency ransom demands, particularly targeting healthcare and education sectors. Law enforcement actions include a 2022 seizure of multiple Phorpiex C2 servers by the US Federal Bureau of Investigation (FBI), though the botnet remains partially active due to its decentralized P2P design.

🔍 Detection Indicators

Behavioral signatures include high volumes of outbound UDP traffic on non‑standard ports and repeated DHT lookups to known peer IPs. Network indicators include User‑Agent strings such as "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko" and HTTP requests to URLs containing patterns like /gate.php? or /check.php?. File hashes for known Phorpiex samples are published in the VirusTotal database (e.g., SHA256: a3b8c9d...) and can be used with SIEM rules. Registry persistence keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun frequently use the string "phorpiex" in mutex names (e.g., GlobalPhorpiexMutex).

☠️ Risk & Impact

Phorpiex infections have led to data exfiltration of sensitive credentials, financial losses from ransomware payments (often demanded in Bitcoin or Monero), and operational disruption in targeted organizations. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported that between 2019 and 2021, the botnet caused millions of dollars in damages, primarily affecting SMEs and public institutions in North America and Europe.

🛡️ Mitigation

Defenses should include disabling macros in Office documents, implementing strict email filtering with attachment scanning, deploying endpoint detection and response (EDR) tools that monitor for process hollowing and unusual UDP traffic, and applying patches for vulnerabilities exploited in macro‑based attacks (e.g., CVE‑2017‑11882). Organizations can also block known Phorpiex IOCs using threat‑intelligence feeds from sources like the MITRE ATT&CK framework (technique T1059.005 – Visual Basic).

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.