Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 33 IP / 26 hostnames
Phorpiex, also known as Trik and associated in recent reporting with the Twizt variant, is a long-running Windows malware family active since at least 2011.
Profile source: Mallory opens in a new tabPhorpiex
Phorpiex, also known as Trik and associated in recent reporting with the Twizt variant, is a long-running Windows malware family active since at least 2011. It is best characterized as a worm-enabled botnet and downloader platform that evolved from spam operations into a multi-purpose criminal ecosystem used for mass malspam and sextortion, follow-on payload delivery, cryptocurrency theft, cryptomining deployment, and ransomware distribution. Documented follow-on payloads have included XMRig miners and ransomware families such as LockBit Black and Global Group-like strains.
Phorpiex targets Windows systems and combines several propagation and monetization mechanisms in one codebase. It spreads through removable USB media and shared or remote drives by copying itself and using shortcut-based execution tricks, while some variants also inventory disks and removable media as part of propagation logic. The malware establishes persistence through Windows autorun mechanisms and self-copying into writable system or user locations. Multiple analyses also describe defense-evasion behavior including deletion of Mark-of-the-Web metadata, API hashing or string obfuscation, attempts to weaken Microsoft Defender protections, and selective geofencing or locale-based exclusions that avoid execution in certain countries, including CIS-region systems in some Twizt builds.
Operationally, Phorpiex functions as both a botnet and a loader. Variants fetch configuration data and additional payloads from command-and-control infrastructure, while newer Twizt activity also uses a peer-to-peer layer that improves resilience against takedown. Reported botnet capabilities include command retrieval, spam distribution, TCP flooding associated with DDoS behavior, and decentralized peer management with encrypted communications. Some builds use UPnP-based NAT traversal to expose inbound connectivity on infected hosts.
A prominent monetization feature is cryptocurrency theft via clipboard hijacking. Twizt variants monitor clipboard activity, validate wallet-address formats, and replace copied addresses with attacker-controlled alternatives across numerous blockchain ecosystems. Other observed monetization includes deployment of Monero miners and large-scale sextortion spam campaigns sent through infected hosts or abused SMTP infrastructure. Sextortion operations attributed to Phorpiex have claimed webcam compromise and demanded cryptocurrency payments at scale, reaching millions of targets per campaign.
Phorpiex has been repeatedly linked to broader crimeware delivery chains and malware-as-a-service ecosystems. Recent investigations tied Phorpiex-distributed payloads to the Needle platform and to shared delivery infrastructure overlapping with other commodity malware operations. The family has also been observed in phishing and malspam campaigns using archive attachments and weaponized shortcut files to deliver ransomware. Its long operational history, mixed centralized and P2P architecture, worm propagation, and flexible payload delivery make it a durable and adaptable criminal malware platform.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b701daded4124260a49040d83dec15c627b8e4a1a04dc378aae7fecfca3abf3 440e51a8a43b43896889549dc960753da592c474c02cb5111962759d0599823e 4f94b0323fe0c179e15f786f83da6a4634295f237202d135ead8b33b29106876 68ee5cbb84faf7f0368c0683eaa376f18459aa6789dddd955965045251091143 fc850941be7a2e75cabbf7151688a702c9dcd0aa880fe1dfed078eafc2215d8a 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 6747147c5ba29975a557d88cd22114478890a0a0a613f36512dcb730e4efe965 944a6ff7edb3991a3f60e19d26f23ad21054adc53109cfcdbb5d101a84a7971b dd17e871204619a3de34126e366221b64e684ec13e24dfc871698abe343acbff fbf4ef28c4b49c6304d23a738afabf8981590eae8585834bf24e3c7e87163c1a Reported operators
A single 11KB Phorpiex worm dropper hit MalwareBazaar at 02:10 UTC on April 20, 2026.
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.