Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Phorpiex

36
Global rank
26 infographic chevron month
Month rank
49 infographic chevron week
Week rank
0
IOCs

Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.

Botnet
Type
Unknown
Origin
1 August, 2016
First seen
27 August, 2026
Last seen
Also known as
Trik

How to analyze Phorpiex with ANY.RUN

Type
Unknown
Origin
1 August, 2016
First seen
27 August, 2026
Last seen

IOCs

IP addresses
48.209.138.168
94.16.122.201
74.179.77.204
192.109.139.79
192.210.186.206
77.72.1.44
185.241.208.33
203.159.90.46
195.177.94.118
158.94.209.17
89.208.97.134
95.100.102.9
2.22.255.166
94.154.32.99
155.103.69.250
91.92.240.17
176.65.139.201
216.172.173.7
185.27.134.99
217.217.97.53
Hashes
a8a284f377cb9f21c53e5553234ecb693dc4c2c38f3306b6cde4aead5e05e913
92c6531a09180fae8b2aae7384b4cea9986762f0c271b35da09b4d0e733f9f45
c43668eec4a8d88a5b3a06a84f8846853fe33e54293c2db56899a5a5dfb4d944
41c91a9c93d76295746a149dce7ebb3b9ee2cb551d84365fff108e59a61cc304
30eedefcdd6870576babcba3fcd73f44ad563b4087bf8d1dd4e4663433f44858
3c3d7da255fb0241c53e030035b443c2fc1c3ae84109041fcc53347881b6c2bf
3ee8bf7fb2731b8350a5ecfdbda3f6a5935a9477f29e909b81ddcebe56887d12
180195558475b32abedb88b3103c06ee464148809986b78de32d8fdba897c516
8aae675bb39439e681976562dfa1f9d6f902bcffe540d31882f01b9e71d93584
44e8a165811c771298a104687d11bc11465181f939963c4c2224dc8ae151f2fa
933e2b77ee23a4bf6dab40964a47acecf928aa71f3ec6d21cc63fcb7c418f8ea
4412319ef944ebcca9581cbacb1d4e1dc614c348d1dfc5d2faaaad863d300209
036bacf3bd34365006eac2a78e4520a953a6250e9550dcf9c9d4b0678c225b4c
a8bd235303668981563dfb5aae338cb802817c4060e2c199b7c84901d57b7e1e
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
e09f42c398d688dce168570291f1f92d079987deda3099a34adb9e8c0522b30c
35bb2f189c643dcf52ecf037603d104035ecdc490bf059b7736e58ef7d821a09
d6a5fe39cd672781b256e0e3102f7022635f1d4bb7cfcc90a80fffe4d0f3877e
93332c49fab1deb87dac6cb5d313900cb20e6e1ba928af128a1d549a44256f68
Domains
students16.screenconnect.com
bmpincorporated.com
sixmexicos.com
gulf.moneroocean.stream
effectively32.infinityfree.me
mon-blanc-03.cfd
deliverymailreport.co.za
tarkioweb.com
release-assets.githubusercontent.com
sunix-technology.com
savannahadventureslimited.com
czd.ru.com
trf.kookapp.pro
inventorychanger.com
dns.google
wealthishealth.free.je
www.serdaregitim.com
t.me
eccmice.com
www.dropbox.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://maper.info/26tkr5
https://www.google.com/
https://urlhaus.abuse.ch/downloads/text/
http://91.92.242.236/files-129312398/files/file_e99b2c2df468a74c.exe
http://91.92.242.236/files-129312398/files/file_865d4f3e8fa37c05.exe
http://62.60.226.140/files/nels/cli.exe
http://91.92.242.236/files-129312398/files/file_542ee73385a72661.exe
http://193.104.58.65/rumpyu14th.png
http://193.104.58.65/img_gas.png
http://62.60.226.140/amka/random.exe
http://130.12.180.141/screenconnect.clientsetup.exe
http://62.60.226.140/files/1781548144/ql0ijz0.exe
http://62.60.226.140/files/7061144442/nxumfoe.exe
http://107.172.172.216/125/img_000358.png
http://193.104.58.65/obofile.png
http://62.60.226.140/files/gold/random.exe
http://91.92.242.236/files-129312398/files/file_28ae045da50f3847.exe
http://62.60.226.140/files/omega/file.exe
http://62.60.226.140/files/7782139129/tz2szvl.exe
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

What is Phorpiex malware?

Phorpiex is a botnet malware written in C++ that was first spotted back in 2016. Originally, it relied on brute forcing for infiltrating devices through the use of default login credentials. Once on the system, the malicious software received instructions from its authors to deliver extra payloads, thus, serving as a loader. Another feature of the threat is its worm-like behavior that allows it to spread via USB drives.

The malware has been used to infect thousands of devices and install various malicious programs, including ransomware and cryptojacking software. It was also employed in sextortion campaigns that involved distributing phishing emails to users from a leaked database, requesting them to pay to the attackers.

In August 2021, it was deactivated by its operators. During this time, Phorpiex’s source code was put up for sale on a dark web forum. This, however, did not spell the end to the malware, as it was back in operation by the end of the year. This time, the malware heavily targeted virtual currency users through crypto clipping. In these attacks, the botnet automatically replaced victims’ crypto wallet addresses with those of the operators, duping them into transferring funds to the criminals.

In 2024, the malware made a serious comeback as part of another large-scale phishing campaign, sending thousands of emails to victims containing the LockBit ransomware.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Phorpiex botnet execution process

To see how the latest version of the malware operates on an infected system, let’s upload its sample to ANY.RUN’s cloud malware sandbox .

Phorpiex analysis in ANY.RUN Phorpiex sample analysis in ANY.RUN sandbox

After Phorpiex malware is delivered and installed on the machine, it adds a registry key to ensure it runs automatically at startup. It also introduces a mutex to prevent multiple instances from running.

Phorpiex analysis in ANY.RUN Phorpiex process graph in ANY.RUN

Since the malware acts as a worm, it instantly starts infecting removable and shared drives by creating copies of itself on these drives to spread. Phorpiex can compromise system security by disabling security features, allowing it to maintain persistence and continue spreading.

The malware also tries to connect to malicious command and control (C2) servers. If the connection is successful, Phorpiex downloads and executes additional malware, such as cryptominers or ransomware like LockBit Black.

As mentioned, Phorpiex can be used to send spam emails, including those with malicious attachments or links. In the absence of active C2 servers, Phorpiex can operate in P2P mode, enabling it to continue spreading and executing malware without relying on centralized control.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Phorpiex malware technical details

Phorpiex is a modular malware, meaning that it has dedicated modules for different types of malicious activities.

The key function of Phorpiex since its launch has been creating a network of bots, compromised systems, which then can be leveraged to conduct malicious activities. Unlike botnets, such as Mirai or Gafgyt, Phorpiex does not use its infrastructure to carry out DDoS attacks. Instead, it has been observed to orchestrate spam email campaigns. In 2018, the malware’s database of over 40 million target email addresses was exposed, revealing the extent of its campaigns. A typical spam email from Phorpiex involves an attachment containing a malicious payload and a message, accompanying it, that asks the user to open the attachment.

The malware is equipped with a loader module that lets it distribute other malicious payloads on the systems it manages to infiltrate. Over the years, it has been utilized to push different malware families, including Nemty and GandCrab

It also has crypto clipping capabilities, supporting dozens of wallet types and cryptocurrencies. The malware changes the crypto addresses copied by the victim to the clipboard and tricks them into sending their virtual funds to the attacker’s wallets.

The latest version of the malware operates in the peer-to-peer mode. This means that devices infected with Phorpiex can not only spread the malware further but also control other machines in the network.

Some of the older variants of the malware also used XMRig to mine the Monero cryptocurrency using the resources of the infected hosts.

The malware possesses anti-vm and anti-debugging capabilities. It ensures persistence by modifying registry entries to run automatically. Some versions of the malware are also capable of disabling common detection systems, such as Windows Defender.

Phorpiex malware distribution methods

According to some estimates, since its release, Phorpiex has been used to infect over a million devices. One of the primary reasons for its extensive reach is its worm module, which allows it to self-propagate across networks and devices. A worm module is a component of malware that enables it to replicate itself and spread to other systems without the need for human interaction.

However, the worm module is not the only method Phorpiex uses for distribution. It has also been known to spread through spam emails. These emails often contain malicious attachments or links to download sites. Additionally, Phorpiex has been observed being dropped by other loader malware.

Conclusion

Phorpiex remains a significant cybersecurity threat to organizations and individuals. To ensure the infection does not occur it is crucial to implement proper security controls. One of the key components of a solid security strategy is the use of a malware analysis sandbox.

ANY.RUN's interactive sandbox offers a number of features that simplify and accelerate the process of malware analysis, as it:

  • Identifies threats in files and URLs in less than 40 seconds.
  • Allows for direct interaction with the samples and the system, similar to a regular computer.
  • Provides customizable Windows and Linux virtual machines to suit your specific needs.
  • Generates detailed reports outlining the nature and extent of the identified threats.
  • Reveals all malicious activities related to the network, registry, and files, as well as the processes involved.

Create your FREE ANY.RUN account today!

HAVE A LOOK AT

DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More
LokiBot screenshot
LokiBot
lokibot loader trojan
LokiBot was developed in 2015 to steal information from a variety of applications. Despite the age, this malware is still rather popular among cybercriminals.
Read More
Kratos screenshot
Kratos
kratos
Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.
Read More
ClickLock screenshot
ClickLock
clicklock
ClickLock is a macOS information stealer and remote backdoor distributed via deceptive, terminal-based social engineering pages. Once executed, it bypasses Gatekeeper checks by stripping download quarantine flags and signing its executable with ad-hoc digital certificates. If users resist its initial demands, the malware initiates high-frequency background loops that repeatedly kill vital operating system applications to force plaintext password entry. It exfiltrates captured browser data, system keychain credentials, and cryptocurrency wallets to a Telegram bot before establishing a permanent backdoor.
Read More
Netwalker screenshot
Netwalker
netwalker ransomware
Netwalker is ransomware — it belongs to a malware family which encrypts files and demands users to pay a ransom to get their data back. Netwalker utilizes several sophisticated techniques, such as process hollowing and code obfuscation to target corporate victims.
Read More
Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More