Phorpiex is a long-running criminal botnet and malware operation associated with large-scale spam distribution, malware delivery, credential theft, and data exfiltration. It has historically been used to propagate additional payloads and monetize infected systems through botnet-enabled cybercrime. The malware ecosystem tied to Phorpiex has been linked to theft-oriented activity and post-compromise collection from victim hosts. Phorpiex is primarily recognized as a financially motivated cybercriminal operation rather than a state-sponsored actor. Its infrastructure has been observed in overlap or proximity with other criminal malware operations, indicating use of shared hosting providers or adjacent criminal infrastructure. In the supplied facts, known Phorpiex command-and-control infrastructure appeared on the same subnet as infrastructure used by a separate Fuery operation, suggesting at minimum shared bulletproof-hosting usage, though not proving common operators. High-confidence characterization of Phorpiex supports its role as a botnet used for initial access, credential theft, and exfiltration in support of financially motivated cybercrime. The available facts here do not directly support ransomware or extortion activity by Phorpiex in this specific context.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.