Phoenix Cryptolocker is a ransomware threat actor known from reporting that links it to ransomware proceeds laundered through the Garantex cryptocurrency exchange. It has been named alongside other major ransomware operations including Conti, Black Basta, LockBit, and NetWalker in connection with illicit transaction flows. Based on the available information, Phoenix Cryptolocker is associated with ransomware-driven extortion activity, but the supplied facts do not provide further high-confidence detail on its malware lineage, victimology, operational structure, geographic attribution, or specific intrusion tradecraft beyond its involvement in ransomware proceeds.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.