Description
Phoenix is a remote access tool for Android devices that extensively spies on victims, capturing screenshots, stealing the screen unlock gesture, and logging incoming SMS messages. It disguises itself as a Google Calendar application, abuses the Accessibility API and device administrator rights, and receives operator commands over a websocket connection. Researchers published a full reverse engineering in 2024, and leaked source code later confirmed the analysis.
Stats
- First seen
- April 2022
- Last seen
- September 2026
Alert name variants
| Alert Name |
|---|
| DOS.Virus.Phoenix |
| Gen:Variant.Application.Miner.Phoenix.2 |
| Phoenix.2000 |
| Win32.Backdoor.Phoenix |
| Win32.Infostealer.Phoenix |
| Win32.Trojan.Phoenix |
| Win64.Ransomware.Phoenix |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Phoenix exploit kit post-compromise behavior |

