{"id":2803,"date":"2021-05-21T22:35:46","date_gmt":"2021-05-22T03:35:46","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2803"},"modified":"2021-05-21T22:35:47","modified_gmt":"2021-05-22T03:35:47","slug":"phorpiex-an-ancient-threat-that-resurfaces-again","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/","title":{"rendered":"Phorpiex, an ancient threat that resurfaces again"},"content":{"rendered":"\n<p>Cybersecurity researchers have discovered that a decade-old botnet has a new feature that allows it to send millions of phishing emails, specifically sextortion threats from a single hijacked PC. The Phorpiex botnet, also known as Trik, is a worm that infects PCs via phishing emails, then downloads more malware payloads from its command and control center. Phorpiex, in fact, was known for distributing other malware families through spam and for driving large-scale sextortion and crypto mining spam campaigns that actually affected many users on the network.<\/p>\n\n\n\n<p>This is an enduring botnet known for its extortion campaigns and for using outdated worms that spread via removable USB drives and instant messaging applications, it began diversifying its infrastructure in recent years to become more resilient and deliver more dangerous payloads.<\/p>\n\n\n\n<p>Today, the Phorphiex botnet continues to maintain a large botnet and generates a wide range of malicious activities but &#8230; As of 2018 this expanded to include cryptocurrency mining, increased data exfiltration activities, and ransomware delivery Additionally, the bot&#8217;s installer was observed to be distributing Avaddon, Knot, BitRansomware (DSoftCrypt \/ ReadMe), Nemty, GandCrab, and Pony ransomware, among other malicious programs.<\/p>\n\n\n\n<p>The Phorpiex botnet has a reputation for being simplistic and lacking in robustness, and has been hijacked by security researchers in the past. Its tactics, techniques, and procedures (TTPs) have remained largely static, with common commands, file names, and execution patterns almost unchanged from early 2020 to 2021.<\/p>\n\n\n\n<p>However, to support its expansion, Phorpiex has changed some of its commands and Control architecture (C2) moves away from its traditional hosting, favoring Domain Generation Algorithm (DGA) domains over brand domains and static.<\/p>\n\n\n\n<p>Unfortunately, cybercriminals are always looking to update and improve their threats, and this evolution characterizes the role of botnets in the threat landscape and the motivation of attackers to persist and remain effective.<\/p>\n\n\n\n<p>Related reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/the-first-ransomware-in-the-world-when-it-all-started\/\">The First Ransomware in the world \u2013 When it all started<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/ping-of-death-one-of-the-first-threats-on-the-net\/\">Ping of Death, One of the first threats on the net<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have discovered that a decade-old botnet has a new feature that allows it to send millions of phishing emails, specifically sextortion threats from a single hijacked PC. The Phorpiex botnet, also known as Trik, is a worm that infects PCs via phishing emails, then downloads more malware payloads from its command and control [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2809,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2803","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Phorpiex, an ancient threat that resurfaces again - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Cybercriminals do not rest and always seek to improve, a proof of this is a botnet called Phorpiex, which was see for the first time in 2010.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Phorpiex, an ancient threat that resurfaces again - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Cybercriminals do not rest and always seek to improve, a proof of this is a botnet called Phorpiex, which was see for the first time in 2010.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-22T03:35:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-22T03:35:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Phorpiex.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"728\" \/>\n\t<meta property=\"og:image:height\" content=\"380\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Phorpiex, an ancient threat that resurfaces again\",\"datePublished\":\"2021-05-22T03:35:46+00:00\",\"dateModified\":\"2021-05-22T03:35:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/\"},\"wordCount\":328,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Phorpiex.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/\",\"name\":\"Phorpiex, an ancient threat that resurfaces again - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Phorpiex.jpg\",\"datePublished\":\"2021-05-22T03:35:46+00:00\",\"dateModified\":\"2021-05-22T03:35:47+00:00\",\"description\":\"Cybercriminals do not rest and always seek to improve, a proof of this is a botnet called Phorpiex, which was see for the first time in 2010.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Phorpiex.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/Phorpiex.jpg\",\"width\":728,\"height\":380},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/phorpiex-an-ancient-threat-that-resurfaces-again\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Phorpiex, an ancient threat that resurfaces again\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Phorpiex, an ancient threat that resurfaces again - Truxgo Server Blog","description":"Cybercriminals do not rest and always seek to improve, a proof of this is a botnet called Phorpiex, which was see for the first time in 2010.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/","og_locale":"es_MX","og_type":"article","og_title":"Phorpiex, an ancient threat that resurfaces again - Truxgo Server Blog","og_description":"Cybercriminals do not rest and always seek to improve, a proof of this is a botnet called Phorpiex, which was see for the first time in 2010.","og_url":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-22T03:35:46+00:00","article_modified_time":"2021-05-22T03:35:47+00:00","og_image":[{"width":728,"height":380,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Phorpiex.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Phorpiex, an ancient threat that resurfaces again","datePublished":"2021-05-22T03:35:46+00:00","dateModified":"2021-05-22T03:35:47+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/"},"wordCount":328,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Phorpiex.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/","url":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/","name":"Phorpiex, an ancient threat that resurfaces again - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Phorpiex.jpg","datePublished":"2021-05-22T03:35:46+00:00","dateModified":"2021-05-22T03:35:47+00:00","description":"Cybercriminals do not rest and always seek to improve, a proof of this is a botnet called Phorpiex, which was see for the first time in 2010.","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Phorpiex.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/Phorpiex.jpg","width":728,"height":380},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/phorpiex-an-ancient-threat-that-resurfaces-again\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Phorpiex, an ancient threat that resurfaces again"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2803","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2803"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2803\/revisions"}],"predecessor-version":[{"id":2812,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2803\/revisions\/2812"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2809"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2803"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2803"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2803"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}