Researchers reported that Phoenix emerged as a VB.NET malware-as-a-service operation that goes beyond keylogging to steal credentials and other sensitive data from nearly 20 browsers, along with email, FTP, and chat clients. The malware also captures keystrokes and clipboard contents, takes screenshots, and can download additional payloads, while exfiltrating stolen information through SMTP, FTP, or Telegram.
Analysis found Phoenix uses layered anti-analysis and anti-detection techniques, including string encryption, obfuscation, anti-VM checks, attempts to disable Windows Defender, and an anti-AV component designed to terminate more than 80 security and analysis tools. The malware has been distributed through phishing campaigns using weaponized RTF and Microsoft Office documents exploiting CVE-2017-11882, and researchers linked it to the earlier Alpha keylogger based on similarities in code, configuration, marketing, and timeline, indicating Phoenix is a rebranded evolution of that malware family.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Cybereason reported that the Phoenix malware family first emerged at the end of July 2019. The VB.NET malware-as-a-service keylogger functioned more broadly as an infostealer and was linked to phishing delivery using weaponized Office documents.
Cybereason’s Nocturnus team published an analysis of Phoenix, detailing its credential theft, keylogging, screenshot capture, anti-analysis features, and exfiltration methods. The report also assessed Phoenix as a rebranded evolution of the earlier Alpha keylogger based on code, configuration, marketing, and timeline similarities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.