Phobos

Aliases: Java NotDharma

First seen
2019-01-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 12:40:55

Targeted industries: healthcare-and-pharmaceutical financial-services manufacturing technology-and-telecommunications

Context

Phobos exploits open or poorly secured RDP ports to sneak inside networks and execute a ransomware attack, encrypting files and demanding a ransom be paid in bitcoin for returning the files, which in this case are locked with a .phobos extension.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_INDICATOR_KB_ID_Ransomware_Phobos (yara-rule)
  • MALPEDIA_Win_Phobos_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • CrowdStrike — Ransomware Preparedness A Call To Action (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
  • blackberry.com — Wp Spark State Of Ransomware (report)
  • coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)
  • paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
  • ESET — Eset Threat Report Q22020 (report)
  • youtube.com — Watch (report)
  • zdnet.com — New Phobos Ransomware Exploits Weak Security To Hit Targets Around The World (report)
  • ransomlook.io — Phobos (report)
  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • Kaspersky — 104452 (report)
  • mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
  • mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
  • npa.go.jp — Ransomdamagerecovery (report)
  • Cisco Talos — Deep Dive Into Phobos Ransomware (report)
  • acronis.com — 8Base Ransomware Stays Unseen For A Year (report)
  • twitter.com — 1674718854549831681 (report)
  • logpoint.com — Defending Against 8Base (report)
  • trellix.com — Phobos Stealthy Ransomware That Operated Under The Radar Until Now (report)
  • circleid.com — 20240530 A Dns Investigation Of The Phobos Ransomware 8Base Attack (report)
  • blogs.vmware.com — 8Base Ransomware A Heavy Hitting Player (report)
  • blogs.blackberry.com — Zebra2104 (report)
  • advanced-intel.com — Inside Phobos Ransomware Dharma Past Underground (report)

External references