Fenix is a financially motivated botnet active since 2022 that has targeted users of government services in Mexico since 2024, with particular focus on tax-paying individuals. It exploits tax season through spoofing and impersonation of official government portals to lure victims and deliver malware. Its infrastructure has been described as a multi-tiered operation that separates payload delivery, command-and-control, and control-panel hosting from a central server used for data collection and management. Fenix is assessed to operate within the broader cybercriminal ecosystem and may monetize operations by selling initial access to other criminal actors, including ransomware affiliates. The group’s activity aligns with credential theft, initial access operations, and financially driven cybercrime targeting Mexican government-service users.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.