Skip to content

Phoenix

Phoenix is a malware name used for multiple distinct families, most prominently a Windows VB.NET information stealer/keylogger active since 2019, an Android remote-access and banking malware lineage derived from Cerberus, and a later custom backdoor associated with the Iranian threat group MuddyWater.

Profile source: Mallory opens in a new tab

Phoenix

Family profile

Phoenix is a malware name used for multiple distinct families, most prominently a Windows VB.NET information stealer/keylogger active since 2019, an Android remote-access and banking malware lineage derived from Cerberus, and a later custom backdoor associated with the Iranian threat group MuddyWater. Because the same name is applied to unrelated malware, attribution and classification require platform and campaign context.

The best-documented Phoenix variant on Windows is a malware-as-a-service infostealer and keylogger written in VB.NET. It emerged in 2019 and was marketed in underground communities as a low-cost commodity stealer. Its capabilities include credential theft from numerous browsers, mail clients, FTP software, and chat clients; keylogging; clipboard theft; screenshot capture; host profiling; and downloading additional payloads. It has also been observed stealing browser cookies and cryptocurrency-related data in some campaigns. Exfiltration has been reported over channels including SMTP, FTP, Telegram, and direct network upload. Anti-analysis and defense-evasion features include obfuscation, encrypted strings, anti-debugging, anti-VM checks, attempts to disable Microsoft Defender, and process termination targeting security tools. Delivery has been strongly associated with phishing and malspam, including weaponized Office or RTF documents exploiting CVE-2017-11882, as well as lure-based distribution through fake tools and malware delivery services. Researchers have linked this Windows Phoenix to the earlier Alpha keylogger and noted code similarities with other commodity .NET stealers such as Snake, Matiex, 404, and Cheetah.

A separate Android Phoenix family has been described both as a remote access trojan and as a banking trojan lineage. Android Phoenix abuses Accessibility Services and device administration privileges to spy on victims, steal SMS messages, capture screenshots, log input, harvest unlock patterns, and support remote interaction. Reporting in 2024 identified Phoenix as a Cerberus-derived banking trojan sold on underground forums, while reverse engineering of Android/Phoenix samples showed dynamic module loading, command handling, and surveillance-oriented functionality. Related reporting indicates Phoenix code also informed later Android malware such as Perseus.

Phoenix is also the name of a custom backdoor used by MuddyWater, an Iranian state-aligned espionage actor also tracked as Seedworm, Mango Sandstorm, Static Kitten, and TA450. From 2025 onward, MuddyWater was observed delivering Phoenix through malicious documents with macros and spearphishing campaigns, including operations targeting North African energy organizations and broader MENA government and international targets. In this context, Phoenix functions as a .NET or PowerShell-associated backdoor used for persistent access, intelligence collection, and follow-on intrusion activity as part of MuddyWater’s broader custom implant ecosystem.

Separately, “Phoenix” has also appeared as a ransomware brand name in reporting on Evil Corp rebranding, but that usage refers to an operation name rather than a clearly defined standalone malware family in the same sense as the Windows stealer, Android trojan, or MuddyWater backdoor.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Session Hijacking
  • Spoofing

Reported operators

Threat actors

3 named in public reporting
INDRIK SPIDER

After the US Department of the Treasury Office of Foreign Asset Control (OFAC) sanctioned Evil Corp over Dridex in December, 2019, the group went through a rapid set of name and branding changes to their ransomware, cycling through many names including WastedLocker, Hades, Phoenix, Grief, Macaw, and now, possibly, Entropy.

MuddyWater

MuddyWater ... pour diffuser des malwares comme « Phoenix, FakeUpdate, StealthCache et Chromium_Stealer ».

Turla

“It also started using a new framework that we call Phoenix...”

Exploited software

Vulnerabilities linked to Phoenix

1 CVEs

MITRE ATT&CK

Phoenix in ATT&CK

56 distinct techniques

Techniques

56 techniques
T1555 Credentials from Password Stores T1566.001 Spearphishing Attachment T1567 Exfiltration Over Web Service T1082 System Information Discovery T1033 System Owner/User Discovery T1027 Obfuscated Files or Information T1113 Screen Capture T1091 Replication Through Removable Media T1497 Virtualization/Sandbox Evasion T1622 Debugger Evasion T1105 Ingress Tool Transfer T1071.003 Mail Protocols T1071.002 File Transfer Protocols T1057 Process Discovery T1012 Query Registry T1562 Impair Defenses T1056.001 Keylogging T1552.001 Credentials In Files T1016 System Network Configuration Discovery T1140 Deobfuscate/Decode Files or Information T1070 Indicator Removal T1555.003 Credentials from Web Browsers T1112 Modify Registry T1027.002 Software Packing T1203 Exploitation for Client Execution T1083 File and Directory Discovery T1005 Data from Local System T1059.003 Windows Command Shell T1218.001 Compiled HTML File T1036 Masquerading T1071 Application Layer Protocol T1566 Phishing T1055 Process Injection T1539 Steal Web Session Cookie T1041 Exfiltration Over C2 Channel T1486 Data Encrypted for Impact T1574.006 Dynamic Linker Hijacking T1027.013 Encrypted/Encoded File T1056 Input Capture T1547 Boot or Logon Autostart Execution T1071.001 Web Protocols T1059.007 JavaScript T1219 Remote Access Tools T1546.008 Accessibility Features T1204.002 Malicious File T1068 Exploitation for Privilege Escalation T1059.005 Visual Basic T1189 Drive-by Compromise T1589 Gather Victim Identity Information T1497.001 System Checks T1590 Gather Victim Network Information T1543 Create or Modify System Process T1584 Compromise Infrastructure T1586 Compromise Accounts T1021 Remote Services T1586.002 Email Accounts

Reporting

Research mentioning Phoenix

Jan 1
Cybereason

THREAT ANALYSIS REPORT: Snake Infostealer Malware

Researchers detailed ongoing Snake Keylogger activity in which attackers deliver the .NET-based infostealer through phishing emails carrying archive files, malicious executables, exploit-laden RTF documents abusing CVE-2017-11882, and Excel attachments with password-protected VBA macros. In one analyzed chain, a lure such as SeptemberOrderlist.pdf.exe decrypted intermediate .NET assemblies before launching the final payload, while another used base64-encoded PowerShell to download a Snake downloader, retrieve an RC4-encrypted DLL, and deploy the malware through process hollowing. Snake is designed to steal credentials and other sensitive data from more than 50 applications, including browsers, email and FTP clients, communication tools, wireless profiles, and Windows product information, while also capturing keystrokes, screenshots, clipboard contents, host details, geolocation, and time data. The malware can persist through scheduled tasks or Startup-folder registry changes, evade defenses by killing security tools, adding Windows Defender exclusions, and deleting itself, and exfiltrate stolen data over SMTP, FTP, or Telegram via HTTPS. Multiple researchers said Snake shares strong code and loader similarities with commodity stealers such as FormBook, Agent Tesla, Matiex, 404, Cheetah, and Phoenix, pointing to code reuse or shared tooling in the cybercrime ecosystem.

Nov 4
Fortinet Threat Research

Deep Dive into a Fresh Variant of Snake Keylogger Malware | FortiGuard Labs

Jun 28
Hp Wolf Threat Research

Snake Keylogger's Many Skins: Analysing Code Reuse Among Infostealers | HP Wolf Security

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.