Last seven days
- First activity
- Aug 6, 2026
- Last activity
- Aug 12, 2026
- Feed role
- C2 / Distribution
- Host form
- 63 IP / 22 hostnames
Phorpiex, also known as Trik and associated in recent reporting with the Twizt variant, is a long-running Windows malware family active since at least 2011.
Profile source: Mallory opens in a new tabPhorpiex
Phorpiex, also known as Trik and associated in recent reporting with the Twizt variant, is a long-running Windows malware family active since at least 2011. It is best characterized as a worm-enabled botnet and downloader platform that evolved from spam operations into a multi-purpose criminal ecosystem used for mass malspam and sextortion, follow-on payload delivery, cryptocurrency theft, cryptomining deployment, and ransomware distribution. Documented follow-on payloads have included XMRig miners and ransomware families such as LockBit Black and Global Group-like strains.
Phorpiex targets Windows systems and combines several propagation and monetization mechanisms in one codebase. It spreads through removable USB media and shared or remote drives by copying itself and using shortcut-based execution tricks, while some variants also inventory disks and removable media as part of propagation logic. The malware establishes persistence through Windows autorun mechanisms and self-copying into writable system or user locations. Multiple analyses also describe defense-evasion behavior including deletion of Mark-of-the-Web metadata, API hashing or string obfuscation, attempts to weaken Microsoft Defender protections, and selective geofencing or locale-based exclusions that avoid execution in certain countries, including CIS-region systems in some Twizt builds.
Operationally, Phorpiex functions as both a botnet and a loader. Variants fetch configuration data and additional payloads from command-and-control infrastructure, while newer Twizt activity also uses a peer-to-peer layer that improves resilience against takedown. Reported botnet capabilities include command retrieval, spam distribution, TCP flooding associated with DDoS behavior, and decentralized peer management with encrypted communications. Some builds use UPnP-based NAT traversal to expose inbound connectivity on infected hosts.
A prominent monetization feature is cryptocurrency theft via clipboard hijacking. Twizt variants monitor clipboard activity, validate wallet-address formats, and replace copied addresses with attacker-controlled alternatives across numerous blockchain ecosystems. Other observed monetization includes deployment of Monero miners and large-scale sextortion spam campaigns sent through infected hosts or abused SMTP infrastructure. Sextortion operations attributed to Phorpiex have claimed webcam compromise and demanded cryptocurrency payments at scale, reaching millions of targets per campaign.
Phorpiex has been repeatedly linked to broader crimeware delivery chains and malware-as-a-service ecosystems. Recent investigations tied Phorpiex-distributed payloads to the Needle platform and to shared delivery infrastructure overlapping with other commodity malware operations. The family has also been observed in phishing and malspam campaigns using archive attachments and weaponized shortcut files to deliver ransomware. Its long operational history, mixed centralized and P2P architecture, worm propagation, and flexible payload delivery make it a durable and adaptable criminal malware platform.
C2 tracking
Derp observations, rolling seven-day window
Samples
30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 01be18e5bd3d04c79f8db21b72c06b84e724628e24f978a98aa86b4cb5b10499 067e4d534c2c4b0808b3e895d5df93f46fed2718984d5a61e13f2a01ac610215 4911b1593b03a4f312d8314762cd9e3b529fde33f34a61a4f2081f137529ef7c a835f1601b2834fbeb9a3b4b3156d0d0e5ddeac3d9ca0500f5cbfe832d6958b4 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 Reported operators
A single 11KB Phorpiex worm dropper hit MalwareBazaar at 02:10 UTC on April 20, 2026.
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.