Phoenix is a ransomware threat actor publicly identified in connection with the March 2021 intrusion at CNA Financial. The group was associated with the deployment of Phoenix Locker, also referred to as Phoenix CryptoLocker, during that incident. In the CNA intrusion, Phoenix gained initial access through a fake browser update delivered via a legitimate website, then escalated privileges, moved laterally, established persistence on additional systems, conducted internal reconnaissance, and used legitimate tools and valid credentials to reduce detection. Before ransomware deployment, the operators disabled monitoring and security tooling, destroyed or disabled certain backups, staged data from internal file shares, and exfiltrated unstructured data to cloud storage. They then deployed ransomware broadly across the environment, reportedly affecting a large number of systems including remote endpoints connected through VPN. Phoenix demonstrated capabilities spanning initial access, privilege escalation, lateral movement, persistence, reconnaissance, defense evasion, data exfiltration, and post-compromise enterprise-wide ransomware deployment. The victimology directly supported here centers on a major U.S. insurance company, with exposed data affecting employees, former employees, dependents, and some customers. Phoenix has been discussed in public reporting as potentially related to Evil Corp operations because of claimed code similarities between Phoenix Locker and other Evil Corp-associated ransomware families such as WastedLocker and Hades. However, no U.S. government agency was confirmed to have established such a relationship in this case, and CNA stated that its investigation found no confirmed nexus between the Phoenix group responsible for the attack and any sanctioned entity. Given that uncertainty, Phoenix is best characterized here as a ransomware actor linked with high confidence to the CNA attack, while any stronger attribution to Evil Corp remains unconfirmed on the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against CNA Financial, gaining initial access via a fake browser update delivered through a legitimate website, escalating privileges, moving laterally, conducting reconnaissance with legitimate tools and credentials, disabling security tools and backups, exfiltrating data via MEGAsync, and deploying ransomware across the environment.
Identified as the group responsible for the ransomware attack against CNA Financial.
Ransomware threat actor identified by CNA as responsible for the attack; used Phoenix CryptoLocker to encrypt ~15,000 devices and systems, including remote endpoints connected via VPN. Reported as possibly linked to Evil Corp, but CNA states no confirmed nexus.
Ransomware actor referenced for the CNA Financial intrusion using Phoenix Locker (noted as a Hades variant).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.