Netskope Threat Labs

Phorpiex

ATP Sandbox Adv. HeuristicsAV

Phorpiex is a botnet that spreads via removable drives and spam campaigns and delivers various payloads, including ransomware and clipper modules that swap cryptocurrency addresses. Its worm like propagation through USB storage and network shares keeps infections circulating even without email delivery, and its modular design lets operators rent its infrastructure. The family has been active for over a decade, and its clipper module made it a fixture of cryptocurrency theft campaigns.

First seen
March 2022
Last seen
October 2026
Alert Name
Gen:Variant.Phorpiex.1
Gen:Variant.Worm.Phorpiex.10
Gen:Variant.Worm.Phorpiex.127
Gen:Variant.Worm.Phorpiex.153
Gen:Variant.Worm.Phorpiex.2
Gen:Variant.Worm.Phorpiex.24
Gen:Variant.Worm.Phorpiex.25
Gen:Variant.Worm.Phorpiex.30
Gen:Variant.Worm.Phorpiex.31
Gen:Variant.Worm.Phorpiex.55