Skip to content

Phorpiex

Phorpiex, also known as Trik, is a long-running Windows malware botnet and worm that evolved from an IRC-controlled spam bot into a modular malware delivery platform.

Profile source: Mallory opens in a new tab

Phorpiex

Family profile

Phorpiex, also known as Trik, is a long-running Windows malware botnet and worm that evolved from an IRC-controlled spam bot into a modular malware delivery platform. Its architecture has included the Trik IRC bot, the HTTP-based Tldr loader, and later the Twizt component, which added peer-to-peer resilience. Phorpiex has been associated with large-scale sextortion spam, malware distribution, cryptocurrency mining, cryptocurrency clipboard hijacking, and delivery of secondary payloads including ransomware and stealers. It has also been used as an access and delivery platform for other criminal operators.

Phorpiex is notable for combining botnet, worm, and loader behavior. Historical variants could download and execute additional binaries, self-update, brute-force SMTP credentials, and mass-mail malicious attachments. Later Tldr-based variants established persistence, disabled or weakened Windows security controls, removed evidence of internet-origin markings, and downloaded numbered modules or additional payloads from command-and-control infrastructure. Tldr variants also implemented clipboard hijacking for multiple cryptocurrency wallet formats and could validate downloaded payloads cryptographically before execution.

Self-propagation has been a defining feature across multiple Phorpiex generations. The malware has spread through phishing and spam campaigns, fake software distribution, exploit kits, other malware, instant messaging, and removable USB drives. It has used worm modules for removable-drive propagation and file infection, and separate modules such as a VNC worm and NetBIOS worm to expand infections. The VNC worm component has been observed scanning for exposed VNC services, brute-forcing weak passwords, and simulating user input to force remote systems to download and execute malware. Twizt-era activity also showed continued botnet operation with peer-to-peer communications and router port-forwarding abuse via UPnP to maintain reachability behind NAT.

Phorpiex has primarily targeted Windows systems and has infected very large numbers of hosts globally. Reporting has described more than one million infected Windows computers at various points, with broad geographic distribution across Asia, Africa, the Americas, and elsewhere. The botnet has been observed in both consumer and enterprise contexts and has been linked to campaigns affecting universities, as well as broad opportunistic spam and malware-delivery operations.

Monetization has included sextortion spam, spam-for-hire, cryptojacking through XMRig, cryptocurrency clipping, and ransomware delivery. Phorpiex has been linked to distribution or staging of ransomware families including Avaddon, Knot, BitRansomware, Nemty, and GandCrab, and to delivery of other malware such as Raccoon Stealer, Predator The Thief, and DiamondFox. Some variants also collected file listings and exfiltrated data from infected systems. The botnetโ€™s spam operations have sent extortion, phishing, and malware-laden emails at scale, while its clipper functionality has targeted numerous cryptocurrency wallet types.

Operationally, Phorpiex has shown repeated infrastructure changes, including migration from IRC to HTTP and later partial adoption of peer-to-peer communications. It has also experienced disruption, including apparent backend hijacking that caused infected hosts to uninstall the malware, and a later claimed shutdown and attempted sale of source code. Despite such disruptions, subsequent activity demonstrated continued or revived operations. Phorpiex remains significant as an enduring commodity botnet whose modular design, worm capabilities, and role in follow-on ransomware and malware delivery have made it a persistent threat in the cybercrime ecosystem.

Capabilities

  • Brute Force
  • Credential Theft
  • Crypto Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 4, 2026
Last activity
Sep 11, 2026
Feed role
C2 / Distribution
Host form
38 IP / 52 hostnames

Leading locations

  • US24
  • DE13
  • CN8
  • NL4
  • KR3
  • HK2
  • BR1
  • ES1
  • FI1
  • GB1
  • IE1
  • IN1

Leading providers

  • FEMO IT SOLUTIONS LIMITED8
  • Amazon.com, Inc.7
  • Omegatech LTD7
  • Amazon.com, Inc.6
  • Cloudflare, Inc.6
  • China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch2

Infrastructure traits

  • Hosting 55
  • Anycast 6

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
menuPass

Campaign: ็Žฐๅฝนๅ†›ไบบ11 (Active Army11) ... Observed commodity malware: Phorpiex and Emotet.

TWIZT

A single 11KB Phorpiex worm dropper hit MalwareBazaar at 02:10 UTC on April 20, 2026.

MITRE ATT&CK

Phorpiex in ATT&CK

59 distinct techniques

Techniques

59 techniques
T1041 Exfiltration Over C2 Channel T1587.001 Malware T1091 Replication Through Removable Media T1518 Software Discovery T1496 Resource Hijacking T1547.009 Shortcut Modification T1566 Phishing T1046 Network Service Discovery T1562 Impair Defenses T1547.001 Registry Run Keys / Startup Folder T1112 Modify Registry T1115 Clipboard Data T1105 Ingress Tool Transfer T1566.001 Spearphishing Attachment T1189 Drive-by Compromise T1071 Application Layer Protocol T1036 Masquerading T1053.005 Scheduled Task T1135 Network Share Discovery T1568.002 Domain Generation Algorithms T1564 Hide Artifacts T1569.002 Service Execution T1070 Indicator Removal T1110 Brute Force T1059.001 PowerShell T1083 File and Directory Discovery T1082 System Information Discovery T1497.001 System Checks T1197 BITS Jobs T1033 System Owner/User Discovery T1021.002 SMB/Windows Admin Shares T1021 Remote Services T1560 Archive Collected Data T1204.002 Malicious File T1055.002 Portable Executable Injection T1486 Data Encrypted for Impact T1090.003 Multi-hop Proxy T1027.002 Software Packing T1071.001 Web Protocols T1029 Scheduled Transfer T1095 Non-Application Layer Protocol T1497 Virtualization/Sandbox Evasion T1622 Debugger Evasion T1585 Establish Accounts T1204 User Execution T1005 Data from Local System T1071.003 Mail Protocols T1614 System Location Discovery T1090 Proxy T1566.002 Spearphishing Link T1598 Phishing for Information T1562.001 Disable or Modify Tools T1070.004 File Deletion T1543.003 Windows Service T1570 Lateral Tool Transfer T1114 Email Collection T1027 Obfuscated Files or Information T1059.003 Windows Command Shell T1059 Command and Scripting Interpreter

Reporting

Research mentioning Phorpiex

Jul 14
Pointwild

Phorpiex: Inside the Botnet Powering Global Sextortion Spam Operations | Point Wild

Researchers reported that the Phorpiex botnet is being used to run large-scale sextortion spam operations while also delivering additional malware and monetizing infected systems. Point Wild traced a multi-stage infection chain that downloaded payloads from 178.16.54.109, profiled victims through ip-api.com geolocation lookups, and skipped execution in countries including the US, UK, Canada, and Germany. The final payload was identified as the Phorpiex Twizt downloader, which established persistence and connected victims to botnet command-and-control infrastructure. Analysis from Point Wild and Bitsight shows the botnet supports multiple criminal revenue streams beyond spam. Infected hosts were observed making high volumes of outbound SMTP connections consistent with mass mailing and abuse of internal mail relays to evade blacklist-based filtering, while sextortion emails falsely claimed webcam compromise and demanded $1,200 in Bitcoin. Researchers also found Phorpiex capable of clipboard hijacking, TCP flooding, ransomware-related activity tied to Twizt, and downloading XMRig to mine Monero, underscoring the botnet's role as a flexible platform for spam, malware distribution, and follow-on attacks.

Jan 1
Sophos Threat Research

New Lemon Duck variants exploiting Microsoft Exchange Server | SOPHOS

LemonDuck has been documented as a cross-platform malware operation that moved beyond Monero mining into credential theft, lateral movement, email propagation, security-tool tampering, and delivery of follow-on payloads on both Windows and Linux systems. Researchers said the malware spreads through phishing, USB and network shares, brute-force attacks against services including RDP, SSH, SMB, MSSQL, and Redis, and exploitation of known flaws such as CVE-2017-0144 and Microsoft Exchange ProxyLogon. The campaign also used fileless PowerShell execution, scheduled tasks, and WMI event subscriptions for persistence, while deploying components such as XMRig, password-dumping tools, and in some cases Mimikatz and Ramnit.

Jan 1
Sophos Threat Research

New Lemon Duck variants exploiting Microsoft Exchange Server | SOPHOS

Jun 15
Netbytesec

Lemon-Duck Cryptominer Technical Analysis

Aug 3
The Record Media

LemonDuck botnet evolves to allow hands-on-keyboard intrusions | The Record from Recorded Future News

Jul 29
Microsoft General

When coin miners evolve, Part 2: Hunting down LemonDuck and LemonCat attacks | Microsoft Security Blog

Jul 22
Microsoft General

When coin miners evolve, Part 1: Exposing LemonDuck and LemonCat, modern mining malware infrastructure | Microsoft Security Blog

May 7
Talosintelligence Other

Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.