Skip to content

Phorpiex

Phorpiex, also known as Trik and associated in recent reporting with the Twizt variant, is a long-running Windows malware family active since at least 2011.

Profile source: Mallory opens in a new tab

Phorpiex

Family profile

Phorpiex, also known as Trik and associated in recent reporting with the Twizt variant, is a long-running Windows malware family active since at least 2011. It is best characterized as a worm-enabled botnet and downloader platform that evolved from spam operations into a multi-purpose criminal ecosystem used for mass malspam and sextortion, follow-on payload delivery, cryptocurrency theft, cryptomining deployment, and ransomware distribution. Documented follow-on payloads have included XMRig miners and ransomware families such as LockBit Black and Global Group-like strains.

Phorpiex targets Windows systems and combines several propagation and monetization mechanisms in one codebase. It spreads through removable USB media and shared or remote drives by copying itself and using shortcut-based execution tricks, while some variants also inventory disks and removable media as part of propagation logic. The malware establishes persistence through Windows autorun mechanisms and self-copying into writable system or user locations. Multiple analyses also describe defense-evasion behavior including deletion of Mark-of-the-Web metadata, API hashing or string obfuscation, attempts to weaken Microsoft Defender protections, and selective geofencing or locale-based exclusions that avoid execution in certain countries, including CIS-region systems in some Twizt builds.

Operationally, Phorpiex functions as both a botnet and a loader. Variants fetch configuration data and additional payloads from command-and-control infrastructure, while newer Twizt activity also uses a peer-to-peer layer that improves resilience against takedown. Reported botnet capabilities include command retrieval, spam distribution, TCP flooding associated with DDoS behavior, and decentralized peer management with encrypted communications. Some builds use UPnP-based NAT traversal to expose inbound connectivity on infected hosts.

A prominent monetization feature is cryptocurrency theft via clipboard hijacking. Twizt variants monitor clipboard activity, validate wallet-address formats, and replace copied addresses with attacker-controlled alternatives across numerous blockchain ecosystems. Other observed monetization includes deployment of Monero miners and large-scale sextortion spam campaigns sent through infected hosts or abused SMTP infrastructure. Sextortion operations attributed to Phorpiex have claimed webcam compromise and demanded cryptocurrency payments at scale, reaching millions of targets per campaign.

Phorpiex has been repeatedly linked to broader crimeware delivery chains and malware-as-a-service ecosystems. Recent investigations tied Phorpiex-distributed payloads to the Needle platform and to shared delivery infrastructure overlapping with other commodity malware operations. The family has also been observed in phishing and malspam campaigns using archive attachments and weaponized shortcut files to deliver ransomware. Its long operational history, mixed centralized and P2P architecture, worm propagation, and flexible payload delivery make it a durable and adaptable criminal malware platform.

Capabilities

  • Crypto Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 6, 2026
Last activity
Aug 12, 2026
Feed role
C2 / Distribution
Host form
63 IP / 22 hostnames

Leading locations

  • CN15
  • US12
  • DE9
  • IR9
  • CA4
  • DZ4
  • KR4
  • NL4
  • RU4
  • UZ3
  • IE2
  • SG2

Leading providers

  • Iran Telecommunication Company PJS8
  • FEMO IT SOLUTIONS LIMITED5
  • CHINA UNICOM China169 Backbone4
  • Telecom Algeria4
  • Omegatech LTD3
  • Amazon.com, Inc.2

Infrastructure traits

  • Hosting 44
  • Vpn 4
  • Proxy 3
  • Tor 3
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
TWIZT

A single 11KB Phorpiex worm dropper hit MalwareBazaar at 02:10 UTC on April 20, 2026.

MITRE ATT&CK

Phorpiex in ATT&CK

37 distinct techniques

Reporting

Research mentioning Phorpiex

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.