Last seven days
- First activity
- Sep 21, 2026
- Last activity
- Sep 27, 2026
- Feed role
- C2 / Distribution
- Host form
- 14 IP / 11 hostnames
Phorpiex, also known as Trik, is a long-running Windows malware botnet and worm that evolved from an IRC-controlled spam bot into a modular malware delivery platform.
Profile source: Mallory opens in a new tabPhorpiex
Phorpiex, also known as Trik, is a long-running Windows malware botnet and worm that evolved from an IRC-controlled spam bot into a modular malware delivery platform. Its architecture has included the Trik IRC bot, the HTTP-based Tldr loader, and later the Twizt component, which added peer-to-peer resilience. Phorpiex has been associated with large-scale sextortion spam, malware distribution, cryptocurrency mining, cryptocurrency clipboard hijacking, and delivery of secondary payloads including ransomware and stealers. It has also been used as an access and delivery platform for other criminal operators.
Phorpiex is notable for combining botnet, worm, and loader behavior. Historical variants could download and execute additional binaries, self-update, brute-force SMTP credentials, and mass-mail malicious attachments. Later Tldr-based variants established persistence, disabled or weakened Windows security controls, removed evidence of internet-origin markings, and downloaded numbered modules or additional payloads from command-and-control infrastructure. Tldr variants also implemented clipboard hijacking for multiple cryptocurrency wallet formats and could validate downloaded payloads cryptographically before execution.
Self-propagation has been a defining feature across multiple Phorpiex generations. The malware has spread through phishing and spam campaigns, fake software distribution, exploit kits, other malware, instant messaging, and removable USB drives. It has used worm modules for removable-drive propagation and file infection, and separate modules such as a VNC worm and NetBIOS worm to expand infections. The VNC worm component has been observed scanning for exposed VNC services, brute-forcing weak passwords, and simulating user input to force remote systems to download and execute malware. Twizt-era activity also showed continued botnet operation with peer-to-peer communications and router port-forwarding abuse via UPnP to maintain reachability behind NAT.
Phorpiex has primarily targeted Windows systems and has infected very large numbers of hosts globally. Reporting has described more than one million infected Windows computers at various points, with broad geographic distribution across Asia, Africa, the Americas, and elsewhere. The botnet has been observed in both consumer and enterprise contexts and has been linked to campaigns affecting universities, as well as broad opportunistic spam and malware-delivery operations.
Monetization has included sextortion spam, spam-for-hire, cryptojacking through XMRig, cryptocurrency clipping, and ransomware delivery. Phorpiex has been linked to distribution or staging of ransomware families including Avaddon, Knot, BitRansomware, Nemty, and GandCrab, and to delivery of other malware such as Raccoon Stealer, Predator The Thief, and DiamondFox. Some variants also collected file listings and exfiltrated data from infected systems. The botnetโs spam operations have sent extortion, phishing, and malware-laden emails at scale, while its clipper functionality has targeted numerous cryptocurrency wallet types.
Operationally, Phorpiex has shown repeated infrastructure changes, including migration from IRC to HTTP and later partial adoption of peer-to-peer communications. It has also experienced disruption, including apparent backend hijacking that caused infected hosts to uninstall the malware, and a later claimed shutdown and attempted sale of source code. Despite such disruptions, subsequent activity demonstrated continued or revived operations. Phorpiex remains significant as an enduring commodity botnet whose modular design, worm capabilities, and role in follow-on ransomware and malware delivery have made it a persistent threat in the cybercrime ecosystem.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 9838584fba1ebdf51d3fcd9cb0d5461d92001e574adafc826dc3ce914f7304b8 a4a0dceae8a383fc471efdc3cb0f043fd6e31ae842fd8951757cc9c3e601c634 e9554b920a4a65df1dd5809afcf5e9d0c5cd448528a03c7a232f83abcc565cd5 03e6043a9dc35b10400bd0e81a62977b05e7ecf941524673bdcdcae9e012cb07 1ed96e7149dab574c95e0f43dc69335012fc79f2d2d3163bc630a8e2f6bdfaee 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 420f60b9cc01514778bd506dcab312fe35ce47700dbe064252cbca6f693fe8d3 6d679e86b520abd2285b22bc2c974468f05e6f0c4d8156cfa4f33ecfce1f9804 Reported operators
MITRE ATT&CK
Reporting
Researchers reported that the Phorpiex botnet is being used to run large-scale sextortion spam operations while also delivering additional malware and monetizing infected systems. Point Wild traced a multi-stage infection chain that downloaded payloads from 178.16.54.109, profiled victims through ip-api.com geolocation lookups, and skipped execution in countries including the US, UK, Canada, and Germany. The final payload was identified as the Phorpiex Twizt downloader, which established persistence and connected victims to botnet command-and-control infrastructure. Analysis from Point Wild and Bitsight shows the botnet supports multiple criminal revenue streams beyond spam. Infected hosts were observed making high volumes of outbound SMTP connections consistent with mass mailing and abuse of internal mail relays to evade blacklist-based filtering, while sextortion emails falsely claimed webcam compromise and demanded $1,200 in Bitcoin. Researchers also found Phorpiex capable of clipboard hijacking, TCP flooding, ransomware-related activity tied to Twizt, and downloading XMRig to mine Monero, underscoring the botnet's role as a flexible platform for spam, malware distribution, and follow-on attacks.
LemonDuck has been documented as a cross-platform malware operation that moved beyond Monero mining into credential theft, lateral movement, email propagation, security-tool tampering, and delivery of follow-on payloads on both Windows and Linux systems. Researchers said the malware spreads through phishing, USB and network shares, brute-force attacks against services including RDP, SSH, SMB, MSSQL, and Redis, and exploitation of known flaws such as CVE-2017-0144 and Microsoft Exchange ProxyLogon. The campaign also used fileless PowerShell execution, scheduled tasks, and WMI event subscriptions for persistence, while deploying components such as XMRig, password-dumping tools, and in some cases Mimikatz and Ramnit.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.