Phorpiex, also known as Trik, is a long-running Windows malware botnet and worm that evolved from an IRC-controlled spam bot into a modular malware delivery platform. Its architecture has included the Trik IRC bot, the HTTP-based Tldr loader, and later the Twizt component, which added peer-to-peer resilience. Phorpiex has been associated with large-scale sextortion spam, malware distribution, cryptocurrency mining, cryptocurrency clipboard hijacking, and delivery of secondary payloads including ransomware and stealers. It has also been used as an access and delivery platform for other criminal operators.
Phorpiex is notable for combining botnet, worm, and loader behavior. Historical variants could download and execute additional binaries, self-update, brute-force SMTP credentials, and mass-mail malicious attachments. Later Tldr-based variants established persistence, disabled or weakened Windows security controls, removed evidence of internet-origin markings, and downloaded numbered modules or additional payloads from command-and-control infrastructure. Tldr variants also implemented clipboard hijacking for multiple cryptocurrency wallet formats and could validate downloaded payloads cryptographically before execution.
Self-propagation has been a defining feature across multiple Phorpiex generations. The malware has spread through phishing and spam campaigns, fake software distribution, exploit kits, other malware, instant messaging, and removable USB drives. It has used worm modules for removable-drive propagation and file infection, and separate modules such as a VNC worm and NetBIOS worm to expand infections. The VNC worm component has been observed scanning for exposed VNC services, brute-forcing weak passwords, and simulating user input to force remote systems to download and execute malware. Twizt-era activity also showed continued botnet operation with peer-to-peer communications and router port-forwarding abuse via UPnP to maintain reachability behind NAT.
Phorpiex has primarily targeted Windows systems and has infected very large numbers of hosts globally. Reporting has described more than one million infected Windows computers at various points, with broad geographic distribution across Asia, Africa, the Americas, and elsewhere. The botnet has been observed in both consumer and enterprise contexts and has been linked to campaigns affecting universities, as well as broad opportunistic spam and malware-delivery operations.
Monetization has included sextortion spam, spam-for-hire, cryptojacking through XMRig, cryptocurrency clipping, and ransomware delivery. Phorpiex has been linked to distribution or staging of ransomware families including Avaddon, Knot, BitRansomware, Nemty, and GandCrab, and to delivery of other malware such as Raccoon Stealer, Predator The Thief, and DiamondFox. Some variants also collected file listings and exfiltrated data from infected systems. The botnet’s spam operations have sent extortion, phishing, and malware-laden emails at scale, while its clipper functionality has targeted numerous cryptocurrency wallet types.
Operationally, Phorpiex has shown repeated infrastructure changes, including migration from IRC to HTTP and later partial adoption of peer-to-peer communications. It has also experienced disruption, including apparent backend hijacking that caused infected hosts to uninstall the malware, and a later claimed shutdown and attempted sale of source code. Despite such disruptions, subsequent activity demonstrated continued or revived operations. Phorpiex remains significant as an enduring commodity botnet whose modular design, worm capabilities, and role in follow-on ransomware and malware delivery have made it a persistent threat in the cybercrime ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Campaign: 现役军人11 (Active Army11) ... Observed commodity malware: Phorpiex and Emotet.
A single 11KB Phorpiex worm dropper hit MalwareBazaar at 02:10 UTC on April 20, 2026.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Some Tldr samples have the functionality of a computer worm and can spread through removable drives.
Phorpiex is spread through exploit kits and with the help of other malware... Dropped by RIG EK 2019-05-29
In February of 2021, infected implants also downloaded additional Etherium miners. These miners create scheduled tasks are labeled “WindowsUpdate” but run the miner every minute.
This includes modifying registry keys to disable firewall and antivirus popups or functionality, overriding proxy and browser settings, setting the loader and executables to run at startup, and adding these executables to the authorized application lists.
In February of 2021, infected implants also downloaded additional Etherium miners. These miners create scheduled tasks are labeled “WindowsUpdate” but run the miner every minute.
As the bot loader updates, the key values change to reflect new files, randomized file paths, and masqueraded system files. The example below illustrates a change from SVCHOST to LSASS
First the Zone Identifier is stripped if present... DeleteFileA ; delete the zone.identifier s
Privileges : Check if running as admin (“A”) or user (“U”) using IsUserAnAdmin
Phorpiex bots continuously scan domain names and IP addresses extracted from the configuration. Even if a valid C&C server responds, the malware continues to query other hosts.
The routine get_id_string identifies the following os information: Window Version... Country... 32bit or 64bit
it will scans all drives including USB and remote drives for .exe files and infect them
The purpose of Tldr, and modules such as the VNC Worm and the NetBIOS Worm, is to distribute the botnet as much as possible.
VNC Spreader and autoinfector... checks for port 5900, if port is open it start bruteforce and if logged in, it downloads your file with powershell and bitsadmin
Phorpiex has shifted some of its previous command-and-control (C2) architecture away from its traditional hosting, favoring domain generation algorithm (DGA) domains over branded and static domains.
485 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A long-running malware family used primarily as a dropper and spam botnet, observed here fetching staged payloads directly from hard-coded IP infrastructure and associated with ransomware payload delivery.
Phorpiex is the malware family used in the article’s STIX/TAXII example to illustrate how malware context can be preserved alongside indicators, sightings, labels, and related objects in a threat intelligence feed.
Malware / Outils # Mycelium Framework (botnet) Mirai (botnet) DorkBot (botnet) RageBot (botnet) Phorpiex (botnet) IRCBot.HI (botnet)
Phorpiex is described as a multifunctional botnet malware family used for large-scale spam and sextortion distribution. In this campaign it uses staged downloaders, geolocation checks, persistence, C2 communications, mass SMTP spam delivery, worm-like propagation, clipboard hijacking for cryptocurrency theft, and botnet activity including TCP flooding/DDoS behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.