Researchers reported that the Phorpiex botnet is being used to run large-scale sextortion spam operations while also delivering additional malware and monetizing infected systems. Point Wild traced a multi-stage infection chain that downloaded payloads from 178.16.54.109, profiled victims through ip-api.com geolocation lookups, and skipped execution in countries including the US, UK, Canada, and Germany. The final payload was identified as the Phorpiex Twizt downloader, which established persistence and connected victims to botnet command-and-control infrastructure.
Analysis from Point Wild and Bitsight shows the botnet supports multiple criminal revenue streams beyond spam. Infected hosts were observed making high volumes of outbound SMTP connections consistent with mass mailing and abuse of internal mail relays to evade blacklist-based filtering, while sextortion emails falsely claimed webcam compromise and demanded $1,200 in Bitcoin. Researchers also found Phorpiex capable of clipboard hijacking, TCP flooding, ransomware-related activity tied to Twizt, and downloading XMRig to mine Monero, underscoring the botnet's role as a flexible platform for spam, malware distribution, and follow-on attacks.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Point Wild reported a multi-stage campaign tied to infrastructure associated with the Phorpiex botnet that used downloader stages, geolocation checks, and country-based execution avoidance before deploying the Phorpiex Twizt downloader. The final payload enabled persistence, botnet C2, spam delivery, clipboard hijacking, TCP flooding, and deployment of an XMRig Monero miner, while monetization relied on sextortion emails demanding $1,200 in Bitcoin.
Bitsight published research on ransomware activity involving the Twizt malware and the Phorpiex botnet, documenting the threat's role in the broader malware ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.