In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
Phobos
Phobos is a Windows ransomware family distributed through a ransomware-as-a-service model, in which affiliates conduct intrusions and share proceeds with the operators.
Phobos
Family profile
Phobos is a Windows ransomware family distributed through a ransomware-as-a-service model, in which affiliates conduct intrusions and share proceeds with the operators. It is closely related to Dharma and the broader CrySis lineage, sharing ransom-note conventions, encrypted-file naming patterns, and negotiation practices. Phobos has affected businesses worldwide, particularly small and medium-sized organizations, as well as local governments, emergency services, educational institutions, healthcare providers, and other critical infrastructure entities.
Phobos intrusions commonly begin through exposed or poorly secured Remote Desktop Protocol services and compromised remote desktop connections. The ransomware encrypts victim files and appends identifying information used for ransom negotiations. Customized Phobos variants, including those deployed by 8Base, use AES-256-CBC file encryption with RSA-protected encryption keys. Analyzed variants establish Windows startup persistence, delete shadow copies and backup catalogs, disable recovery features, and disable the Windows firewall. Phobos samples have also been protected with Rex3Packer, and the Fair variant has used fileless, memory-based delivery.
Phobos historically relied primarily on encryption-based extortion, but affiliates subsequently adopted data theft and double extortion. Associated operations include 8Base and Faust; Faust operators have published stolen data through the 8Base and Space Bears leak sites. Phobos-related intrusions have used tools such as MegaSync to transfer stolen data to external cloud storage. Named variants include Eking, Eight, Elbie, Devos, and Faust. OpcJacker, also described as Phobos Crypter in some reporting, is a separate malware family that has been used to load Phobos.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
- Persistence
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
8 named in public reportingIn April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
In April 2024, S-RM’s Cyber Threat Intelligence team identified a Faust operator, an affiliate of the Phobos ransomware-as-a-service group, utilising a new leak site, titled ‘Space Bears’, to extort a victim for a ransom payment.
First discovered in March 2022, 8Base is a ransomware group/operation that uses a customized version of Phobos ransomware and steals data prior to encryption.
The Makop ransomware operators started their infamous criminal business in 2020 leveraging a new variant of the notorious Phobos ransomware.
They can also manifest in even more extreme behavior where RaaS affiliates switch to older “fully owned” ransomware payloads like Phobos...
Several research teams link the group to the Phobos ransomware as a service program (RaaS), and the Space Bears leak site is believed to function as a shared publishing point for activity related to that infrastructure.
Polish authorities arrested a 47-year-old man suspected of involvement in cybercrime and linked him to the Phobos ransomware operation... Phobos is an organized cybercrime group operating a ransomware-as-a-service (RaaS) model, providing its malware to affiliates who carry out attacks and share the profits.
MITRE ATT&CK
Phobos in ATT&CK
54 distinct techniquesTechniques
54 techniquesReporting
Research mentioning Phobos
New Panda Stealer Targets Cryptocurrency Wallets | Trend Micro (US)
Researchers reported that Panda Stealer is being distributed through spam emails carrying malicious Excel attachments and is designed to steal cryptocurrency wallet data, browser information, screenshots, and credentials from applications including NordVPN, Telegram, Discord, and Steam. The malware was described as a modified fork of Collector Stealer and was observed targeting victims in the United States, Australia, Japan, and Germany during a broad spam wave. The malware uses fileless and evasive techniques to avoid detection, including PowerShell, payload hosting on paste.ee, in-memory loading of a .NET assembly, and process hollowing of MSBuild.exe. Investigators also linked the operation to multiple command-and-control and download servers, and said testing activity suggested use of a Shock Hosting VPS and Cassandra Crypter, indicating a coordinated credential- and wallet-theft campaign focused on monetizing stolen crypto assets and account access.
If it sounds too good to be true, it most likely is: Nobody can decrypt the Dharma ransomware
Security researchers said companies claiming to decrypt files locked by Dharma/Crisis ransomware are not defeating the malware’s encryption, which experts described as effectively unbreakable without a flaw or the criminals’ private key. An investigation by Emsisoft and outside researchers challenged Australian firm Fast Data Recovery after it advertised a high chance of recovering Dharma-encrypted files and claimed it could reverse engineer decryption keys, despite specialists including Brett Callow, Michael Gillespie, Bill Siegel, and Fabian Wosar saying no such capability is known to exist. Separate research by Check Point found that Russian service Dr. Shifro allegedly operated as a broker between victims and ransomware operators, buying decryption keys at a discount and reselling recovery at a markup rather than performing true cryptographic recovery. In a sting operation, Check Point observed the service requesting encrypted samples and then contacting the attacker-side email to negotiate key purchases; the researchers linked the activity to iharauch@gmail.com and identified a likely operator in Moscow, estimating profits of about $1,350 per victim and potentially hundreds of thousands of dollars overall.