Netskope Threat Labs

Phobos

ATP Sandbox Adv. HeuristicsAV

Phobos has been around since 2018 and targets small and medium sized businesses using phishing emails with malicious attachments and by exploiting remote desktop services exposed to the internet. Its encryptor locks files with appended extensions and drops ransom notes demanding payment, and its operators have run the family as a straightforward criminal service. Its persistence reflects the continued exposure of remote access services at organizations of modest size.

First seen
May 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Ransomware.Phobos
Document-Office.Trojan.Phobos
Gen:Variant.Ransom.Phobos.154
Gen:Variant.Ransom.Phobos.169
Gen:Variant.Ransom.Phobos.21
Gen:Variant.Ransom.Phobos.25
Trojan.Ransom.Phobos.F
Win32.Ransomware.Phobos
Win64.Trojan.Phobos