faust
- First seen
- 2019-05-01 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:56:30
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector education-and-nonprofits
Context
Faust is a variant of the well-known Phobos ransomware, part of a Ransomware-as-a-Service (RaaS) ecosystem active since around May 2019. Faust employs a double-extortion model, encrypting victim files and threatening to release stolen data if ransom demands are not met. It's distributed via Office document payloads using VBA scripts and known for its fileless attack delivery, enabling stealth and evasion.
Reports & references
- ransomlook.io — Faust (report)
- CISA — Aa24 060A (report)
- truesec.com — A Case Of The Faust Ransomware (report)
- Broadcom/Symantec — Faust Ransomware A Phobos Family Variant (report)