Phobos is a Windows ransomware family distributed through a ransomware-as-a-service model, in which affiliates conduct intrusions and share proceeds with the operators. It is closely related to Dharma and the broader CrySis lineage, sharing ransom-note conventions, encrypted-file naming patterns, and negotiation practices. Phobos has affected businesses worldwide, particularly small and medium-sized organizations, as well as local governments, emergency services, educational institutions, healthcare providers, and other critical infrastructure entities.
Phobos intrusions commonly begin through exposed or poorly secured Remote Desktop Protocol services and compromised remote desktop connections. The ransomware encrypts victim files and appends identifying information used for ransom negotiations. Customized Phobos variants, including those deployed by 8Base, use AES-256-CBC file encryption with RSA-protected encryption keys. Analyzed variants establish Windows startup persistence, delete shadow copies and backup catalogs, disable recovery features, and disable the Windows firewall. Phobos samples have also been protected with Rex3Packer, and the Fair variant has used fileless, memory-based delivery.
Phobos historically relied primarily on encryption-based extortion, but affiliates subsequently adopted data theft and double extortion. Associated operations include 8Base and Faust; Faust operators have published stolen data through the 8Base and Space Bears leak sites. Phobos-related intrusions have used tools such as MegaSync to transfer stolen data to external cloud storage. Named variants include Eking, Eight, Elbie, Devos, and Faust. OpcJacker, also described as Phobos Crypter in some reporting, is a separate malware family that has been used to load Phobos.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
First discovered in March 2022, 8Base is a ransomware group/operation that uses a customized version of Phobos ransomware and steals data prior to encryption.
The Makop ransomware operators started their infamous criminal business in 2020 leveraging a new variant of the notorious Phobos ransomware.
They can also manifest in even more extreme behavior where RaaS affiliates switch to older “fully owned” ransomware payloads like Phobos...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The DuplicateTokenEx API is utilized to create a new access token... The ransomware spawns itself running in the security context of the newly created token.
The DuplicateTokenEx API is utilized to create a new access token that duplicates the token mentioned above... The ransomware spawns itself running in the security context of the newly created token.
Let's skip the boring details that are the same for every ransomware (anti-debug features, deletion of shadow copies, main disk traversal function, etc).
The DuplicateTokenEx API is utilized to create a new access token... The ransomware spawns itself running in the security context of the newly created token.
The DuplicateTokenEx API is utilized to create a new access token that duplicates the token mentioned above... The ransomware spawns itself running in the security context of the newly created token.
The malware takes a snapshot of all processes in the system... The processes are enumerated using the Process32FirstW and Process32NextW APIs.
The malware extracts the major and minor version numbers of the operating system using the GetVersion method.
The files are enumerated using the FindFirstFileW and FindNextFileW methods.
WNetOpenEnumW is used to start an enumeration of all currently connected resources... The enumeration continues by calling the WNetEnumResourceW function.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
96 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family often targeting SMBs through exposed remote desktop services. A free decryptor is available for supported Phobos and 8Base variants.
Phobos is identified in the content as a ransomware family linked to some users of the dismantled First VPN service.
Phobos is described as a ransomware-as-a-service outfit linked to ransomware investigations uncovered through the takedown of First VPN.
A ransomware family referenced via a cracked builder offered on RAMP, lowering the barrier to launching independent ransomware attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.