SYMBOLCOMMON_NAMEaka. SYNONYMS
win.phobos (Back to overview)

Phobos

VTCollection    

MalwareBytes states that Phobos is one of the ransomware families that are distributed via hacked Remote Desktop (RDP) connections. This isn't surprising, as hacked RDP servers are a cheap commodity on the underground market, and can make for an attractive and cost efficient dissemination vector for threat groups.

References
2025-07-17 ⋅ National Police Agency (Japan) ⋅ National Police Agency (Japan)
Phobos/8Base Decryption Tool
8Base Phobos
2024-11-20 ⋅ Trellix ⋅ Jambul Tologonov, John Fokker, Phuc Pham
Phobos: Stealthy Ransomware That Operated Under the Radar - Until Now
8Base CryptXXXX Dharma Phobos
2024-05-30 ⋅ circleid ⋅ WhoisXML API
A DNS Investigation of the Phobos Ransomware 8Base Attack
8Base Phobos
2024-05-21 ⋅ S-RM ⋅ Frank de Korte
Phobos ransomware launches new leak site and pivots towards double extortion
Phobos
2024-03-18 ⋅ PCrisk ⋅ Tomas Meskauskas
FORCE (.FORCE) ransomware virus – removal and decryption options
Phobos
2024-02-19 ⋅ Cyber Geeks ⋅ CyberMasterV
A Technical Analysis of the BackMyData Ransomware Used to Attack Hospitals in Romania
Phobos
2024-02-15 ⋅ DNSC ⋅ Directoratul National de Securitate Cibernetica
Backmydata Ransomware
Phobos
2023-11-23 ⋅ Qualys ⋅ Suraj Mundalik
Unveiling the Deceptive Dance: Phobos Ransomware Masquerading As VX-Underground
Phobos
2023-11-17 ⋅ Cisco Talos ⋅ Guilherme Venere
Understanding the Phobos affiliate structure and activity
Phobos
2023-11-17 ⋅ Cisco Talos ⋅ Guilherme Venere
A deep dive into Phobos ransomware, recently deployed by 8Base group
8Base Phobos
2023-08-23 ⋅ Logpoint ⋅ Anish Bogati, Nischal khadgi
Defending Against 8base: Uncovering Their Arsenal and Crafting Responses
8Base Phobos SmokeLoader SystemBC
2023-07-17 ⋅ Acronis ⋅ Acronis Security
8Base ransomware stays unseen for a year
8Base Phobos SmokeLoader
2023-06-30 ⋅ Twitter (@rivitna2) ⋅ @rivitna2
Twitter thread about relationship between 8Base and Phobos ransomware
8Base Phobos
2023-06-28 ⋅ vmware ⋅ Bria Beathley, Dana Behling, Deborah Snyder, Fae Carlisle
8Base Ransomware: A Heavy Hitting Player
8Base Phobos SmokeLoader SystemBC
2023-02-23 ⋅ CERT.PL ⋅ Jarosław Jedynak, Michał Praszmo
A tale of Phobos - how we almost cracked a ransomware using CUDA
Phobos
2022-05-09 ⋅ Microsoft ⋅ Microsoft 365 Defender Threat Intelligence Team, Microsoft Threat Intelligence Center (MSTIC)
Ransomware-as-a-service: Understanding the cybercrime gig economy and how to protect yourself
AnchorDNS BlackCat BlackMatter Conti DarkSide HelloKitty Hive LockBit REvil FAKEUPDATES Griffon ATOMSILO BazarBackdoor BlackCat BlackMatter Blister Cobalt Strike Conti DarkSide Emotet FiveHands Gozi HelloKitty Hive IcedID ISFB JSSLoader LockBit LockFile Maze NightSky Pandora Phobos Phoenix Locker PhotoLoader QakBot REvil Rook Ryuk SystemBC TrickBot WastedLocker BRONZE STARLIGHT
2022-03-03 ⋅ PARAFLARE ⋅ Bex Nitert
Luci Spools The Fun With Phobos Ransomware
Phobos
2021-11-05 ⋅ Blackberry ⋅ The BlackBerry Research & Intelligence Team
Hunter Becomes Hunted: Zebra2104 Hides a Herd of Malware
Cobalt Strike DoppelDridex Mount Locker Phobos StrongPity
2021-10-07 ⋅ Kaspersky ⋅ Fedor Sinitsyn, Yanis Zinchenko
Ransomware in the CIS
Cryakl Dharma Hakbit Phobos Void
2021-07-22 ⋅ ⋅ Serviciul Român de Informații ⋅ Serviciul Român de Informații
Cyber ​​attack with PHOBOS ransomware application
Phobos
2021-05-11 ⋅ Mal-Eats ⋅ mal_eats
Campo, a New Attack Campaign Targeting Japan
AnchorDNS BazarBackdoor campoloader Cobalt Strike Phobos Snifula TrickBot Zloader
2021-05-10 ⋅ Mal-Eats ⋅ mal_eats
Overview of Campo, a new attack campaign targeting Japan
AnchorDNS BazarBackdoor Cobalt Strike ISFB Phobos TrickBot Zloader
2021-04-27 ⋅ CrowdStrike ⋅ Eben Kaplan, Josh Dalman, Kamil Janton
Ransomware Preparedness: A Call to Action
Dharma GlobeImposter Maze Phobos CIRCUS SPIDER TRAVELING SPIDER
2021-04-26 ⋅ CoveWare ⋅ CoveWare
Ransomware Attack Vectors Shift as New Software Vulnerability Exploits Abound
Avaddon Clop Conti DarkSide Egregor LockBit Mailto Phobos REvil Ryuk SunCrypt
2021-04-12 ⋅ PTSecurity ⋅ PTSecurity
PaaS, or how hackers evade antivirus software
Amadey Bunitu Cerber Dridex ISFB KPOT Stealer Mailto Nemty Phobos Pony Predator The Thief QakBot Raccoon RTM SmokeLoader Zloader
2021-04-02 ⋅ Morphisec ⋅ Michael Gorelik
The “Fair” Upgrade Variant of Phobos Ransomware
Makop Phobos
2021-03-17 ⋅ Palo Alto Networks Unit 42 ⋅ Unit42
Ransomware Threat Report 2021
RansomEXX Dharma DoppelPaymer Gandcrab Mailto Maze Phobos RansomEXX REvil Ryuk WastedLocker
2020-10-13 ⋅ Fortinet ⋅ Xiaopeng Zhang
Deep Analysis – The EKING Variant of Phobos Ransomware
Phobos
2020-07-29 ⋅ ESET Research ⋅ welivesecurity
THREAT REPORT Q2 2020
DEFENSOR ID HiddenAd Bundlore Pirrit Agent.BTZ Cerber ClipBanker CROSSWALK Cryptowall CTB Locker DanaBot Dharma Formbook Gandcrab Grandoreiro Houdini ISFB LockBit Locky Mailto Maze Microcin Nemty NjRAT Phobos PlugX Pony REvil Socelars STOP Tinba TrickBot WannaCryptor
2020-04-24 ⋅ Advanced Intelligence ⋅ Bridgit Sullivan
Inside "Phobos" Ransomware: "Dharma" Past & Underground
Dharma Phobos
2020-03-04 ⋅ CrowdStrike ⋅ CrowdStrike
2020 CrowdStrike Global Threat Report
MESSAGETAP More_eggs 8.t Dropper Anchor BabyShark BadNews Clop Cobalt Strike CobInt Cobra Carbon System Cutwail DanaBot Dharma DoppelDridex DoppelPaymer Dridex Emotet FlawedAmmyy FriedEx Gandcrab Get2 IcedID ISFB KerrDown LightNeuron LockerGoga Maze MECHANICAL Necurs Nokki Outlook Backdoor Phobos Predator The Thief QakBot REvil RobinHood Ryuk SDBbot Skipper SmokeLoader TerraRecon TerraStealer TerraTV TinyLoader TrickBot Vidar Winnti ANTHROPOID SPIDER APT23 APT31 APT39 APT40 BlackTech BuhTrap Charming Kitten CLOCKWORK SPIDER DOPPEL SPIDER FIN7 Gamaredon Group GOBLIN PANDA MONTY SPIDER MUSTANG PANDA NARWHAL SPIDER NOCTURNAL SPIDER PINCHY SPIDER SALTY SPIDER SCULLY SPIDER SMOKY SPIDER Thrip VENOM SPIDER VICEROY TIGER
2020-02-25 ⋅ RSA Conference ⋅ Joel DeCapua
Feds Fighting Ransomware: How the FBI Investigates and How You Can Help
FastCash Cerber Defray Dharma FriedEx Gandcrab GlobeImposter Mamba Phobos Rapid Ransom REvil Ryuk SamSam Zeus
2020-01-17 ⋅ Secureworks ⋅ Keita Yamazaki, Tamada Kiyotaka, You Nakatsuru
Is It Wrong to Try to Find APT Techniques in Ransomware Attack?
Defray Dharma FriedEx Gandcrab GlobeImposter Matrix Ransom MedusaLocker Phobos REvil Ryuk SamSam Scarab Ransomware
2020-01-10 ⋅ Malwarebytes ⋅ Jovi Umawing
Threat spotlight: Phobos ransomware lives up to its name
Phobos
2020-01-01 ⋅ Blackberry ⋅ Blackberry Research
State of Ransomware
Maze MedusaLocker Nefilim Phobos REvil Ryuk STOP
2019-07-24 ⋅ Malwarebytes ⋅ hasherezade
A deep dive into Phobos ransomware
Phobos
2019-01-29 ⋅ CodeWare ⋅ CoveWare
Phobos Ransomware, A Combo of CrySiS and Dharma
Phobos
Yara Rules
[TLP:WHITE] win_phobos_auto (20260917 | Detects win.phobos.)
rule win_phobos_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.phobos."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.phobos"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 1bc0 83c02c 50 e8???????? 59 59 8944242c }
            // n = 7, score = 100
            //   1bc0                 | sbb                 eax, eax
            //   83c02c               | add                 eax, 0x2c
            //   50                   | push                eax
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   59                   | pop                 ecx
            //   8944242c             | mov                 dword ptr [esp + 0x2c], eax

        $sequence_1 = { e8???????? 8b03 83c40c 83c020 6880000000 50 8d4728 }
            // n = 7, score = 100
            //   e8????????           |                     
            //   8b03                 | mov                 eax, dword ptr [ebx]
            //   83c40c               | add                 esp, 0xc
            //   83c020               | add                 eax, 0x20
            //   6880000000           | push                0x80
            //   50                   | push                eax
            //   8d4728               | lea                 eax, [edi + 0x28]

        $sequence_2 = { 663b07 7429 ff4508 668b06 83c602 6685c0 }
            // n = 6, score = 100
            //   663b07               | cmp                 ax, word ptr [edi]
            //   7429                 | je                  0x2b
            //   ff4508               | inc                 dword ptr [ebp + 8]
            //   668b06               | mov                 ax, word ptr [esi]
            //   83c602               | add                 esi, 2
            //   6685c0               | test                ax, ax

        $sequence_3 = { c1ef18 0fb6bfd0c54000 c1e708 33df 8b7df4 c1ef08 23f8 }
            // n = 7, score = 100
            //   c1ef18               | shr                 edi, 0x18
            //   0fb6bfd0c54000       | movzx               edi, byte ptr [edi + 0x40c5d0]
            //   c1e708               | shl                 edi, 8
            //   33df                 | xor                 ebx, edi
            //   8b7df4               | mov                 edi, dword ptr [ebp - 0xc]
            //   c1ef08               | shr                 edi, 8
            //   23f8                 | and                 edi, eax

        $sequence_4 = { 8bcf d3ea 8890e0c64000 8b5654 d3ea 8890e4c64000 8b5658 }
            // n = 7, score = 100
            //   8bcf                 | mov                 ecx, edi
            //   d3ea                 | shr                 edx, cl
            //   8890e0c64000         | mov                 byte ptr [eax + 0x40c6e0], dl
            //   8b5654               | mov                 edx, dword ptr [esi + 0x54]
            //   d3ea                 | shr                 edx, cl
            //   8890e4c64000         | mov                 byte ptr [eax + 0x40c6e4], dl
            //   8b5658               | mov                 edx, dword ptr [esi + 0x58]

        $sequence_5 = { 8b5dfc c1eb18 333c9dd0b54000 8b5df8 23d8 }
            // n = 5, score = 100
            //   8b5dfc               | mov                 ebx, dword ptr [ebp - 4]
            //   c1eb18               | shr                 ebx, 0x18
            //   333c9dd0b54000       | xor                 edi, dword ptr [ebx*4 + 0x40b5d0]
            //   8b5df8               | mov                 ebx, dword ptr [ebp - 8]
            //   23d8                 | and                 ebx, eax

        $sequence_6 = { 884604 884e05 8bc8 c1e818 884607 8bc2 c1e808 }
            // n = 7, score = 100
            //   884604               | mov                 byte ptr [esi + 4], al
            //   884e05               | mov                 byte ptr [esi + 5], cl
            //   8bc8                 | mov                 ecx, eax
            //   c1e818               | shr                 eax, 0x18
            //   884607               | mov                 byte ptr [esi + 7], al
            //   8bc2                 | mov                 eax, edx
            //   c1e808               | shr                 eax, 8

        $sequence_7 = { 57 8d7e0c 57 ff15???????? 57 ff15???????? }
            // n = 6, score = 100
            //   57                   | push                edi
            //   8d7e0c               | lea                 edi, [esi + 0xc]
            //   57                   | push                edi
            //   ff15????????         |                     
            //   57                   | push                edi
            //   ff15????????         |                     

        $sequence_8 = { 8bc7 5f 5d c3 55 8bec 68a4000000 }
            // n = 7, score = 100
            //   8bc7                 | mov                 eax, edi
            //   5f                   | pop                 edi
            //   5d                   | pop                 ebp
            //   c3                   | ret                 
            //   55                   | push                ebp
            //   8bec                 | mov                 ebp, esp
            //   68a4000000           | push                0xa4

        $sequence_9 = { 83c40c 8945f8 8b4dfc 33d2 8955f4 0fb70453 8b7df8 }
            // n = 7, score = 100
            //   83c40c               | add                 esp, 0xc
            //   8945f8               | mov                 dword ptr [ebp - 8], eax
            //   8b4dfc               | mov                 ecx, dword ptr [ebp - 4]
            //   33d2                 | xor                 edx, edx
            //   8955f4               | mov                 dword ptr [ebp - 0xc], edx
            //   0fb70453             | movzx               eax, word ptr [ebx + edx*2]
            //   8b7df8               | mov                 edi, dword ptr [ebp - 8]

    condition:
        7 of them and filesize < 139264
}
Download all Yara Rules