Phorpiex, also known as Trik, is a long-running Windows malware family best known as a worm-driven spam and malware-delivery botnet. It evolved from an earlier IRC-controlled architecture into a more modular ecosystem centered on downloader components such as Tldr and later Twizt. Across its lifespan, Phorpiex has combined self-propagation, bulk email abuse, payload delivery, and cryptocurrency-focused monetization, and has been associated with large global infection volumes.
Phorpiex spreads through multiple channels, including malicious email campaigns, removable USB media, network and remote drives, instant messaging, fake software distribution, exploit kits, and installation by other malware. Its worming behavior has included copying itself to removable or remote storage, creating shortcut-based propagation mechanisms, and in some variants infecting executable files. Additional propagation modules have included VNC- and NetBIOS-based spreading, with brute-force activity against exposed services observed in some components.
The malware establishes persistence on Windows systems by copying itself to writable system or user locations and creating autorun entries. Multiple analyses also describe defense-evasion behavior such as anti-VM and anti-analysis checks, deletion of Zone.Identifier metadata, firewall exception changes, and attempts to weaken Windows security controls including Defender and related protections. Regional exclusion logic has been observed, notably avoiding execution on systems configured for Ukraine in some variants.
Phorpiex’s core operational role is as a downloader and botnet implant. It can retrieve updates, fetch and execute additional payloads, and receive tasking from command-and-control infrastructure. Earlier variants used IRC for command and control, while later generations used HTTP and, in the Twizt branch, peer-to-peer communications with custom encrypted protocols and router port-forwarding via UPnP to improve resilience. The botnet has been used to distribute secondary malware including cryptocurrency miners, stealers, and multiple ransomware families, and it has also been used as a spam platform for both its operators and partner criminal groups.
A defining monetization feature of Phorpiex is cryptocurrency clipping: many variants monitor clipboard contents and replace copied wallet addresses with attacker-controlled alternatives. The family has also been tied to cryptomining through delivery of XMRig, large-scale sextortion and spam campaigns, and malware installation services for other actors. Some reporting additionally describes file-list collection and exfiltration from infected hosts.
Phorpiex has been linked to delivery or staging of ransomware families including Avaddon, BitRansomware, Nemty, GandCrab, and Knot, and to delivery of other commodity malware such as Raccoon Stealer and Predator The Thief. It has remained notable in the cybercrime ecosystem because of its longevity, modularity, and ability to bridge consumer-scale worm propagation with broader criminal services such as spam operations, payload distribution, and access brokerage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A single 11KB Phorpiex worm dropper hit MalwareBazaar at 02:10 UTC on April 20, 2026.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Some Tldr samples have the functionality of a computer worm and can spread through removable drives.
Phorpiex is spread through exploit kits and with the help of other malware... Dropped by RIG EK 2019-05-29
In February of 2021, infected implants also downloaded additional Etherium miners. These miners create scheduled tasks are labeled “WindowsUpdate” but run the miner every minute.
This includes modifying registry keys to disable firewall and antivirus popups or functionality, overriding proxy and browser settings, setting the loader and executables to run at startup, and adding these executables to the authorized application lists.
In February of 2021, infected implants also downloaded additional Etherium miners. These miners create scheduled tasks are labeled “WindowsUpdate” but run the miner every minute.
As the bot loader updates, the key values change to reflect new files, randomized file paths, and masqueraded system files. The example below illustrates a change from SVCHOST to LSASS
First the Zone Identifier is stripped if present... DeleteFileA ; delete the zone.identifier s
Privileges : Check if running as admin (“A”) or user (“U”) using IsUserAnAdmin
Phorpiex bots continuously scan domain names and IP addresses extracted from the configuration. Even if a valid C&C server responds, the malware continues to query other hosts.
The routine get_id_string identifies the following os information: Window Version... Country... 32bit or 64bit
it will scans all drives including USB and remote drives for .exe files and infect them
The purpose of Tldr, and modules such as the VNC Worm and the NetBIOS Worm, is to distribute the botnet as much as possible.
VNC Spreader and autoinfector... checks for port 5900, if port is open it start bruteforce and if logged in, it downloads your file with powershell and bitsadmin
Phorpiex has shifted some of its previous command-and-control (C2) architecture away from its traditional hosting, favoring domain generation algorithm (DGA) domains over branded and static domains.
485 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A long-running malware family used primarily as a dropper and spam botnet, observed here fetching staged payloads directly from hard-coded IP infrastructure and associated with ransomware payload delivery.
Phorpiex is the malware family used in the article’s STIX/TAXII example to illustrate how malware context can be preserved alongside indicators, sightings, labels, and related objects in a threat intelligence feed.
Malware / Outils # Mycelium Framework (botnet) Mirai (botnet) DorkBot (botnet) RageBot (botnet) Phorpiex (botnet) IRCBot.HI (botnet)
Phorpiex is described as a multifunctional botnet malware family used for large-scale spam and sextortion distribution. In this campaign it uses staged downloaders, geolocation checks, persistence, C2 communications, mass SMTP spam delivery, worm-like propagation, clipboard hijacking for cryptocurrency theft, and botnet activity including TCP flooding/DDoS behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.