Phobos is a Windows ransomware family active since at least late 2018 to early 2019 and commonly described as closely related to, or derived from, Dharma/CrySiS. It has operated as a ransomware-as-a-service ecosystem with multiple variants and affiliate teams, including names such as Eking, Eight, Elbie, Devos, and Faust. Phobos has been used against a wide range of organizations worldwide, with repeated reporting of impacts on small and medium-sized businesses as well as county governments, emergency services, educational institutions, healthcare providers, and other critical infrastructure entities.
Phobos intrusions have been strongly associated with compromise of exposed or weakly protected Remote Desktop services, including brute-force or credential-based access to internet-facing systems. Once inside a victim environment, operators commonly perform hands-on-keyboard activity resembling broader targeted ransomware operations: credential theft, privilege escalation, reconnaissance, lateral movement, and broad deployment across reachable systems. Reporting on incidents involving Phobos-linked actors also notes use of administrative tools and post-exploitation techniques to expand access before encryption.
On infected Windows systems, Phobos encrypts files and appends victim- and operator-specific naming elements to encrypted filenames. The family is known for targeting local and network-accessible data and for using anti-recovery measures typical of enterprise ransomware, including deletion of shadow copies and inhibition of recovery options in some observed variants and derivative operations. Multiple reports describe customized Phobos builds used by other groups, notably 8Base and Makop, indicating that the malware is frequently rebranded or modified by affiliates while retaining recognizable Phobos-family structure and behavior.
Historically, Phobos was often characterized as an encryption-focused extortion operation that did not always rely on data theft. That changed by late 2023 and 2024, when affiliates such as Faust were observed exfiltrating victim data and using leak sites for double extortion. Public reporting and government advisories indicate that Phobos operators began pairing encryption with data theft and publication threats, including use of external cloud tools for exfiltration in some cases. This shift aligned Phobos more closely with mainstream big-game ransomware tradecraft.
Technical analysis has shown that some Phobos variants share substantial code and operational overlap with Dharma, while not every build is identical. Research has also identified weaknesses in the key schedule of certain variants, enabling proof-of-concept decryption work under narrow conditions, though this is not broadly practical across the family. Overall, Phobos remains best understood as a long-running, affiliate-driven ransomware family centered on Windows environments, RDP-enabled intrusion paths, and increasingly double-extortion monetization.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
First discovered in March 2022, 8Base is a ransomware group/operation that uses a customized version of Phobos ransomware and steals data prior to encryption.
The Makop ransomware operators started their infamous criminal business in 2020 leveraging a new variant of the notorious Phobos ransomware.
They can also manifest in even more extreme behavior where RaaS affiliates switch to older “fully owned” ransomware payloads like Phobos...
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The DuplicateTokenEx API is utilized to create a new access token... The ransomware spawns itself running in the security context of the newly created token.
The DuplicateTokenEx API is utilized to create a new access token that duplicates the token mentioned above... The ransomware spawns itself running in the security context of the newly created token.
“Embedded Payloads… Phobos actors embedded the ransomware as a hidden payload by using Smokeloader.”
Let's skip the boring details that are the same for every ransomware (anti-debug features, deletion of shadow copies, main disk traversal function, etc).
The DuplicateTokenEx API is utilized to create a new access token... The ransomware spawns itself running in the security context of the newly created token.
The DuplicateTokenEx API is utilized to create a new access token that duplicates the token mentioned above... The ransomware spawns itself running in the security context of the newly created token.
The malware takes a snapshot of all processes in the system... The processes are enumerated using the Process32FirstW and Process32NextW APIs.
The malware extracts the major and minor version numbers of the operating system using the GetVersion method.
The files are enumerated using the FindFirstFileW and FindNextFileW methods.
WNetOpenEnumW is used to start an enumeration of all currently connected resources... The enumeration continues by calling the WNetEnumResourceW function.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phobos is identified in the content as a ransomware family linked to some users of the dismantled First VPN service.
Phobos is described as a ransomware-as-a-service outfit linked to ransomware investigations uncovered through the takedown of First VPN.
A ransomware family referenced via a cracked builder offered on RAMP, lowering the barrier to launching independent ransomware attacks.
Ransomware family whose operators reportedly use Process Hacker as a dual-use utility during attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.