Skip to content

Phobos

Phobos is a Windows ransomware family distributed through a ransomware-as-a-service model, in which affiliates conduct intrusions and share proceeds with the operators.

Phobos

Family profile

Phobos is a Windows ransomware family distributed through a ransomware-as-a-service model, in which affiliates conduct intrusions and share proceeds with the operators. It is closely related to Dharma and the broader CrySis lineage, sharing ransom-note conventions, encrypted-file naming patterns, and negotiation practices. Phobos has affected businesses worldwide, particularly small and medium-sized organizations, as well as local governments, emergency services, educational institutions, healthcare providers, and other critical infrastructure entities.

Phobos intrusions commonly begin through exposed or poorly secured Remote Desktop Protocol services and compromised remote desktop connections. The ransomware encrypts victim files and appends identifying information used for ransom negotiations. Customized Phobos variants, including those deployed by 8Base, use AES-256-CBC file encryption with RSA-protected encryption keys. Analyzed variants establish Windows startup persistence, delete shadow copies and backup catalogs, disable recovery features, and disable the Windows firewall. Phobos samples have also been protected with Rex3Packer, and the Fair variant has used fileless, memory-based delivery.

Phobos historically relied primarily on encryption-based extortion, but affiliates subsequently adopted data theft and double extortion. Associated operations include 8Base and Faust; Faust operators have published stolen data through the 8Base and Space Bears leak sites. Phobos-related intrusions have used tools such as MegaSync to transfer stolen data to external cloud storage. Named variants include Eking, Eight, Elbie, Devos, and Faust. OpcJacker, also described as Phobos Crypter in some reporting, is a separate malware family that has been used to load Phobos.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Persistence

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

8 named in public reporting
BlackRock

In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.

Devos

In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.

Faust

In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.

8Base

First discovered in March 2022, 8Base is a ransomware group/operation that uses a customized version of Phobos ransomware and steals data prior to encryption.

Makop

The Makop ransomware operators started their infamous criminal business in 2020 leveraging a new variant of the notorious Phobos ransomware.

Velvet Tempest

They can also manifest in even more extreme behavior where RaaS affiliates switch to older “fully owned” ransomware payloads like Phobos...

spacebears

Several research teams link the group to the Phobos ransomware as a service program (RaaS), and the Space Bears leak site is believed to function as a shared publishing point for activity related to that infrastructure.

Phobos

Polish authorities arrested a 47-year-old man suspected of involvement in cybercrime and linked him to the Phobos ransomware operation... Phobos is an organized cybercrime group operating a ransomware-as-a-service (RaaS) model, providing its malware to affiliates who carry out attacks and share the profits.

MITRE ATT&CK

Phobos in ATT&CK

54 distinct techniques

Techniques

54 techniques
T1486 Data Encrypted for Impact T1133 External Remote Services T1070.004 File Deletion T1497 Virtualization/Sandbox Evasion T1110 Brute Force T1021 Remote Services T1583 Acquire Infrastructure T1587.001 Malware T1105 Ingress Tool Transfer T1106 Native API T1490 Inhibit System Recovery T1083 File and Directory Discovery T1082 System Information Discovery T1021.002 SMB/Windows Admin Shares T1489 Service Stop T1135 Network Share Discovery T1057 Process Discovery T1134.001 Token Impersonation/Theft T1614.001 System Language Discovery T1134 Access Token Manipulation T1059.003 Windows Command Shell T1548 Abuse Elevation Control Mechanism T1480.002 Mutual Exclusion T1547.001 Registry Run Keys / Startup Folder T1685 Disable or Modify Tools T1047 Windows Management Instrumentation T1027.009 Embedded Payloads T1204.002 Malicious File T1218.005 Mshta T1555.005 Password Managers T1588.002 Tool T1003.001 LSASS Memory T1027.002 Software Packing T1555 Credentials from Password Stores T1566.001 Spearphishing Attachment T1552 Unsecured Credentials T1134.002 Create Process with Token T1048 Exfiltration Over Alternative Protocol T1560 Archive Collected Data T1078 Valid Accounts T1598 Phishing for Information T1657 Financial Theft T1555.003 Credentials from Web Browsers T1686 Disable or Modify System Firewall T1219 Remote Access Tools T1573 Encrypted Channel T1003.005 Cached Domain Credentials T1087.002 Domain Account T1585 Establish Accounts T1071.002 File Transfer Protocols T1567.002 Exfiltration to Cloud Storage T1593 Search Open Websites/Domains T1595.001 Scanning IP Blocks T1213 Data from Information Repositories

Reporting

Research mentioning Phobos

May 4
Trend Micro Research

New Panda Stealer Targets Cryptocurrency Wallets | Trend Micro (US)

Researchers reported that Panda Stealer is being distributed through spam emails carrying malicious Excel attachments and is designed to steal cryptocurrency wallet data, browser information, screenshots, and credentials from applications including NordVPN, Telegram, Discord, and Steam. The malware was described as a modified fork of Collector Stealer and was observed targeting victims in the United States, Australia, Japan, and Germany during a broad spam wave. The malware uses fileless and evasive techniques to avoid detection, including PowerShell, payload hosting on paste.ee, in-memory loading of a .NET assembly, and process hollowing of MSBuild.exe. Investigators also linked the operation to multiple command-and-control and download servers, and said testing activity suggested use of a Shock Hosting VPS and Cassandra Crypter, indicating a coordinated credential- and wallet-theft campaign focused on monetizing stolen crypto assets and account access.

Nov 11
Register Security

If it sounds too good to be true, it most likely is: Nobody can decrypt the Dharma ransomware

Security researchers said companies claiming to decrypt files locked by Dharma/Crisis ransomware are not defeating the malware’s encryption, which experts described as effectively unbreakable without a flaw or the criminals’ private key. An investigation by Emsisoft and outside researchers challenged Australian firm Fast Data Recovery after it advertised a high chance of recovering Dharma-encrypted files and claimed it could reverse engineer decryption keys, despite specialists including Brett Callow, Michael Gillespie, Bill Siegel, and Fabian Wosar saying no such capability is known to exist. Separate research by Check Point found that Russian service Dr. Shifro allegedly operated as a broker between victims and ransomware operators, buying decryption keys at a discount and reselling recovery at a markup rather than performing true cryptographic recovery. In a sting operation, Check Point observed the service requesting encrypted samples and then contacting the attacker-side email to negotiate key purchases; the researchers linked the activity to iharauch@gmail.com and identified a likely operator in Moscow, estimating profits of about $1,350 per victim and potentially hundreds of thousands of dollars overall.

Dec 2
Checkpoint Research

The Ransomware Doctor Without a Cure - Check Point Research