Phoenix CryptoLocker is a ransomware family associated in multiple public reports with the Evil Corp cybercrime ecosystem, also tracked as GOLD DRAKE or Indrik Spider, although some victim-side investigations stated that no government-confirmed attribution to a sanctioned entity had been established for specific incidents. It emerged as one of several ransomware brands used after sanctions pressure complicated payments to operations linked to Evil Corp, alongside names such as WastedLocker, Hades, and PayloadBin.
Phoenix CryptoLocker is used in targeted enterprise intrusions rather than indiscriminate commodity distribution. In the best-documented case, operators gained initial access through a fake browser update delivered via a legitimate website, then escalated privileges, moved laterally across the victim environment, established persistence on additional systems, conducted internal reconnaissance, and used legitimate administrative tools and valid credentials to reduce detection. Before encryption, the operators disabled monitoring and security tooling, interfered with backups, and staged and exfiltrated data from internal servers to cloud storage. The malware was then deployed broadly across the environment, including to remote endpoints connected through corporate VPN access.
The family is associated with double-extortion style operations because intrusions attributed to its operators involved theft of sensitive enterprise data prior to encryption. Reported victimology includes large corporate targets such as the insurance sector. Public reporting also links proceeds from Phoenix CryptoLocker incidents to Russian-linked illicit financial infrastructure used to launder ransomware revenue.
Overall, Phoenix CryptoLocker fits the pattern of a human-operated ransomware operation focused on stealthy post-compromise activity, privilege escalation, lateral movement, defense evasion, data theft, and large-scale encryption of Windows enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Evil Corp began renaming their ransomware operations to different names such as WastedLocker, Hades, Phoenix CryptoLocker, and PayLoadBin.
"...shifted to using ransomware variants such as WastedLocker, Hades, Phoenix CryptoLocker and Payload.bin."
7 distinct techniques documented for this family, organized by ATT&CK tactic.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation attributed in the article to Evil Corp.
Ransomware variant referenced as a source of illicit funds laundered through Garantex.
Ransomware family whose operators’ proceeds were laundered through the Garantex cryptocurrency exchange, per the article.
Ransomware variant explicitly cited as generating proceeds laundered through Garantex.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.