Last seven days
- First activity
- Sep 4, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 38 IP / 52 hostnames
Phorpiex, also known as Trik, is a long-running Windows malware botnet and worm that evolved from an IRC-controlled spam bot into a modular malware delivery platform.
Profile source: Mallory opens in a new tabPhorpiex
Phorpiex, also known as Trik, is a long-running Windows malware botnet and worm that evolved from an IRC-controlled spam bot into a modular malware delivery platform. Its architecture has included the Trik IRC bot, the HTTP-based Tldr loader, and later the Twizt component, which added peer-to-peer resilience. Phorpiex has been associated with large-scale sextortion spam, malware distribution, cryptocurrency mining, cryptocurrency clipboard hijacking, and delivery of secondary payloads including ransomware and stealers. It has also been used as an access and delivery platform for other criminal operators.
Phorpiex is notable for combining botnet, worm, and loader behavior. Historical variants could download and execute additional binaries, self-update, brute-force SMTP credentials, and mass-mail malicious attachments. Later Tldr-based variants established persistence, disabled or weakened Windows security controls, removed evidence of internet-origin markings, and downloaded numbered modules or additional payloads from command-and-control infrastructure. Tldr variants also implemented clipboard hijacking for multiple cryptocurrency wallet formats and could validate downloaded payloads cryptographically before execution.
Self-propagation has been a defining feature across multiple Phorpiex generations. The malware has spread through phishing and spam campaigns, fake software distribution, exploit kits, other malware, instant messaging, and removable USB drives. It has used worm modules for removable-drive propagation and file infection, and separate modules such as a VNC worm and NetBIOS worm to expand infections. The VNC worm component has been observed scanning for exposed VNC services, brute-forcing weak passwords, and simulating user input to force remote systems to download and execute malware. Twizt-era activity also showed continued botnet operation with peer-to-peer communications and router port-forwarding abuse via UPnP to maintain reachability behind NAT.
Phorpiex has primarily targeted Windows systems and has infected very large numbers of hosts globally. Reporting has described more than one million infected Windows computers at various points, with broad geographic distribution across Asia, Africa, the Americas, and elsewhere. The botnet has been observed in both consumer and enterprise contexts and has been linked to campaigns affecting universities, as well as broad opportunistic spam and malware-delivery operations.
Monetization has included sextortion spam, spam-for-hire, cryptojacking through XMRig, cryptocurrency clipping, and ransomware delivery. Phorpiex has been linked to distribution or staging of ransomware families including Avaddon, Knot, BitRansomware, Nemty, and GandCrab, and to delivery of other malware such as Raccoon Stealer, Predator The Thief, and DiamondFox. Some variants also collected file listings and exfiltrated data from infected systems. The botnetโs spam operations have sent extortion, phishing, and malware-laden emails at scale, while its clipper functionality has targeted numerous cryptocurrency wallet types.
Operationally, Phorpiex has shown repeated infrastructure changes, including migration from IRC to HTTP and later partial adoption of peer-to-peer communications. It has also experienced disruption, including apparent backend hijacking that caused infected hosts to uninstall the malware, and a later claimed shutdown and attempted sale of source code. Despite such disruptions, subsequent activity demonstrated continued or revived operations. Phorpiex remains significant as an enduring commodity botnet whose modular design, worm capabilities, and role in follow-on ransomware and malware delivery have made it a persistent threat in the cybercrime ecosystem.
C2 tracking
Derp observations, rolling seven-day window
Samples
13bf1cfedc09e959f6fe09da8c9a687de9ed0d7ba10ca5839a6f0928429a1272 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 0646761fee03120052a9c159131640f946da3a375b29c502a48651c000a382f0 4e36934a2c310fed8556e35a7a96ef60c7d7b378d962aede61ab11a06c25791d 51f3db4cf1fa45032ecf916de6edaa2f2e6e2e47540dba06fbc7e1f4412beade 8eec9f6fdb0c7cb01c7e881a42181b72d70eea5da59f8ed765a04420775b00b6 cf6042bfce6b28fe3ea18ab35865a72c9e109039dd3ebdddd03ac0e7a0bcbbc5 1c98d149fd358406a2fa77fc2c3bbf4f65d04d87f81a2402eab155b186b97cbe a08eeb6cb3b1bcb3331318a87664e5a29f8025bb3eb2bdb74a678d4f423fade5 Reported operators
MITRE ATT&CK
Reporting
Researchers reported that the Phorpiex botnet is being used to run large-scale sextortion spam operations while also delivering additional malware and monetizing infected systems. Point Wild traced a multi-stage infection chain that downloaded payloads from 178.16.54.109, profiled victims through ip-api.com geolocation lookups, and skipped execution in countries including the US, UK, Canada, and Germany. The final payload was identified as the Phorpiex Twizt downloader, which established persistence and connected victims to botnet command-and-control infrastructure. Analysis from Point Wild and Bitsight shows the botnet supports multiple criminal revenue streams beyond spam. Infected hosts were observed making high volumes of outbound SMTP connections consistent with mass mailing and abuse of internal mail relays to evade blacklist-based filtering, while sextortion emails falsely claimed webcam compromise and demanded $1,200 in Bitcoin. Researchers also found Phorpiex capable of clipboard hijacking, TCP flooding, ransomware-related activity tied to Twizt, and downloading XMRig to mine Monero, underscoring the botnet's role as a flexible platform for spam, malware distribution, and follow-on attacks.
LemonDuck has been documented as a cross-platform malware operation that moved beyond Monero mining into credential theft, lateral movement, email propagation, security-tool tampering, and delivery of follow-on payloads on both Windows and Linux systems. Researchers said the malware spreads through phishing, USB and network shares, brute-force attacks against services including RDP, SSH, SMB, MSSQL, and Redis, and exploitation of known flaws such as CVE-2017-0144 and Microsoft Exchange ProxyLogon. The campaign also used fileless PowerShell execution, scheduled tasks, and WMI event subscriptions for persistence, while deploying components such as XMRig, password-dumping tools, and in some cases Mimikatz and Ramnit.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.