Phorpiex, also tracked as Trik, grew from an IRC-controlled Windows worm into a large modular botnet used to spread spam, sextortion emails, cryptocurrency miners, stealers, and ransomware. Early variants copied themselves into hidden directories, set Run key persistence, weakened host defenses by adding firewall exceptions and disabling Windows Defender, and accepted commands to download payloads, brute-force SMTP accounts, and mass-mail ZIP-packed malware. Researchers later tied the botnet to more than 1 million infected systems, with infections observed across 160 countries, and noted propagation through phishing, removable USB drives, instant messaging, fake software sites, and other malware.
Later Phorpiex operations shifted from legacy IRC infrastructure toward HTTP, IP-based, and DGA-backed command-and-control centered on the Tldr loader, while retaining older spam and worming capabilities. The platform delivered secondary payloads including XMRig, Raccoon Stealer, Predator The Thief, GandCrab, Avaddon, Nemty, Knot, Pony, and other ransomware, and also used clipboard hijacking and data exfiltration for monetization. Check Point and Microsoft reported resilient infrastructure, including dedicated subnets and payload validation with RC4 encryption plus RSA-SHA1 signature checks, while a VNC worm module brute-forced exposed port 5900 systems and drove victims to download malware, underscoring Phorpiex's role as a durable criminal distribution service.

Pull IOCs and campaign context straight into your stack.
24 events from the most recent confirmed update back to the earliest known activity.
In May 2021, Microsoft reported that Phorpiex had shifted part of its command-and-control architecture from branded static domains to DGA domains and dedicated IP-based infrastructure. The company also described the botnet as a resilient malware delivery platform distributing ransomware, miners, and other payloads.
Microsoft observed a late-February 2021 Phorpiex extortion wallet campaign that requested $950 and accumulated more than $13,000 in 10 days. This provided a concrete example of the botnet's sextortion monetization.
Microsoft detected Mondfoxia, also known as DiamondFox, on Phorpiex servers in February 2021. This showed Phorpiex infrastructure being used to host or deliver additional malware families.
Microsoft reported that the Phorpiex bot loader was encountered in 160 countries from December 2020 to February 2021, with Mexico, Kazakhstan, and Uzbekistan seeing the most encounters. This highlighted the botnet's broad global reach during that period.
Microsoft observed non-weaponized staging of Knot ransomware on Phorpiex servers in December 2020 and January 2021. This indicated preparation for additional ransomware delivery through the botnet's infrastructure.
Microsoft reported that in late 2020 and early 2021, Phorpiex extortion emails exploited fears about vulnerabilities in teleconferencing applications such as Zoom. This showed the botnet adapting social-engineering lures to current events.
Microsoft said that in summer and fall 2020, many new Phorpiex infections spread archive files delivering BitRansomware and Avaddon. This documented active ransomware distribution through the botnet.
Microsoft reported that Phorpiex maintained largely static tactics, techniques, and procedures from early 2020 to 2021. This indicated operational continuity even as infrastructure diversified.
In January 2020, Check Point published a technical analysis of Phorpiex's Tldr loader and VNC worm, including persistence, anti-analysis, clipper behavior, removable-drive propagation, and payload validation. The report also linked Tldr to the older Trik IRC bot through code and infrastructure overlaps.
In November 2019, Check Point described Phorpiex as infecting more than 1,000,000 Windows hosts, with roughly 15,000 bots online at any given time and up to 100,000 active daily. The report also detailed monetization through sextortion, cryptojacking, clipping, and malware installation.
Check Point noted that the July 2019 Tldr v5.0 variant acquired debug privilege during initialization. This reflected continued development of the loader's capabilities.
Check Point reported that observed Phorpiex modules in 2019 included Tldr, a VNC worm, a NetBIOS worm, an XMRig miner, spam modules, and auxiliary loaders and cleanup modules. This documented the botnet's modular arsenal during that year.
Check Point said researchers discovered more than 4,000 different Tldr samples in 2019, with about 300 configurations and 3,297 domain names and IP addresses. This revealed the scale and diversity of Phorpiex's newer loader ecosystem.
Check Point reported that recent Phorpiex campaigns switched from IRC to a modular architecture centered on the Tldr downloader and largely abandoned IRC communications in 2019. This was a major architectural evolution in the botnet's command-and-control model.
On 2018-05-23, Proofpoint observed the return of an older Trik version, v2.5, using a .NET loader with retained anti-analysis checks. This showed operators reusing legacy code alongside newer variants.
On 2018-05-09, Proofpoint observed Trik receiving instructions to download and distribute GandCrab, Pony, Pushdo, and multiple coin miners. This provided a concrete snapshot of the botnet's payload delivery operations.
After the sinkholing activity, Trik operators stood up four additional command-and-control servers, including reused infrastructure. Following the restoration, campaigns distributing GandCrab resumed.
Proofpoint observed sinkholing activity against Trik command-and-control domains at the end of April 2018 and the beginning of May 2018. A .NET loader variant was seen attempting to connect to an abuse.ch sinkhole after defenders registered several Trik C&C domains.
Microsoft reported that beginning in 2018, Phorpiex activity showed increased data exfiltration and ransomware delivery. This marked a notable expansion from spam and extortion into broader malware delivery and theft.
Proofpoint observed in 2018 that some newly stood-up Trik command-and-control infrastructure had been reused from prior months as far back as 2016. This tied active 2018 operations to older botnet infrastructure.
A 2016 reverse-engineering report documented Phorpiex as an IRC-controlled worm with persistence, anti-analysis checks, SMTP brute forcing, and mass-mailing capabilities. Proofpoint later noted that most of Trik's internals had already been documented in that 2016 post and had changed little by 2018.
Proofpoint said Trik later propagated via removable media storage and email spam. This reflects an operational change in how the botnet spread to new victims.
At a later stage, Trik added Skype-based worming capabilities, though Proofpoint said that behavior appeared to have stopped years before its 2018 report. This marks an expansion in propagation methods beyond removable media and Messenger.
Proofpoint reported that Trik, also known as Phorpiex, had been active for almost a decade and had initially spread via Windows Live Messenger and removable USB storage. This establishes the botnet's early operation as an IRC-controlled worm family.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 366 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
microsoft.com
Open sourceresearch.checkpoint.com
Open sourceresearch.checkpoint.com
Open sourceproofpoint.com
Open sourcebin.re
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.