Phobos is a Windows ransomware family active since 2018 and closely related to Dharma and the earlier CrySiS lineage. It operates as a ransomware-as-a-service ecosystem in which affiliates use closely related variants, including Eking, Eight, Elbie, Devos, and Faust. Phobos has historically targeted small and medium-sized organizations, but Phobos-linked activity has also affected government, emergency services, education, public healthcare, and other critical-infrastructure entities. Attacks commonly obtain access through exposed or weakly secured Remote Desktop Protocol services, after which operators encrypt victim files and demand payment for decryption. Since late 2023, some Phobos affiliates have adopted data theft and double-extortion practices, exfiltrating data and threatening publication through leak sites. The 8Base operation has used customized Phobos-derived ransomware in attacks that combine data theft and encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
First discovered in March 2022, 8Base is a ransomware group/operation that uses a customized version of Phobos ransomware and steals data prior to encryption.
The Makop ransomware operators started their infamous criminal business in 2020 leveraging a new variant of the notorious Phobos ransomware.
They can also manifest in even more extreme behavior where RaaS affiliates switch to older “fully owned” ransomware payloads like Phobos...
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The DuplicateTokenEx API is utilized to create a new access token... The ransomware spawns itself running in the security context of the newly created token.
The DuplicateTokenEx API is utilized to create a new access token that duplicates the token mentioned above... The ransomware spawns itself running in the security context of the newly created token.
“Embedded Payloads… Phobos actors embedded the ransomware as a hidden payload by using Smokeloader.”
Let's skip the boring details that are the same for every ransomware (anti-debug features, deletion of shadow copies, main disk traversal function, etc).
The DuplicateTokenEx API is utilized to create a new access token... The ransomware spawns itself running in the security context of the newly created token.
The DuplicateTokenEx API is utilized to create a new access token that duplicates the token mentioned above... The ransomware spawns itself running in the security context of the newly created token.
The malware takes a snapshot of all processes in the system... The processes are enumerated using the Process32FirstW and Process32NextW APIs.
The malware extracts the major and minor version numbers of the operating system using the GetVersion method.
The files are enumerated using the FindFirstFileW and FindNextFileW methods.
WNetOpenEnumW is used to start an enumeration of all currently connected resources... The enumeration continues by calling the WNetEnumResourceW function.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
94 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phobos is identified in the content as a ransomware family linked to some users of the dismantled First VPN service.
Phobos is described as a ransomware-as-a-service outfit linked to ransomware investigations uncovered through the takedown of First VPN.
A ransomware family referenced via a cracked builder offered on RAMP, lowering the barrier to launching independent ransomware attacks.
Ransomware family whose operators reportedly use Process Hacker as a dual-use utility during attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.