Phobos
Aliases: Java NotDharma
- First seen
- 2019-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:55:25
- Profile updated
- 2026-07-07 12:40:55
Targeted industries: healthcare-and-pharmaceutical financial-services manufacturing technology-and-telecommunications
Context
Phobos exploits open or poorly secured RDP ports to sneak inside networks and execute a ransomware attack, encrypting files and demanding a ransom be paid in bitcoin for returning the files, which in this case are locked with a .phobos extension.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_INDICATOR_KB_ID_Ransomware_Phobos (yara-rule)
- MALPEDIA_Win_Phobos_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- CrowdStrike — Ransomware Preparedness A Call To Action (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- jsac.jpcert.or.jp — Jsac2020 1 Tamada Yamazaki Nakatsuru En (report)
- blackberry.com — Wp Spark State Of Ransomware (report)
- coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)
- paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
- ESET — Eset Threat Report Q22020 (report)
- youtube.com — Watch (report)
- zdnet.com — New Phobos Ransomware Exploits Weak Security To Hit Targets Around The World (report)
- ransomlook.io — Phobos (report)
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- Kaspersky — 104452 (report)
- mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
- mal-eats.net — Campo New Attack Campaign Targeting Japan (report)
- npa.go.jp — Ransomdamagerecovery (report)
- Cisco Talos — Deep Dive Into Phobos Ransomware (report)
- acronis.com — 8Base Ransomware Stays Unseen For A Year (report)
- twitter.com — 1674718854549831681 (report)
- logpoint.com — Defending Against 8Base (report)
- trellix.com — Phobos Stealthy Ransomware That Operated Under The Radar Until Now (report)
- circleid.com — 20240530 A Dns Investigation Of The Phobos Ransomware 8Base Attack (report)
- blogs.vmware.com — 8Base Ransomware A Heavy Hitting Player (report)
- blogs.blackberry.com — Zebra2104 (report)
- advanced-intel.com — Inside Phobos Ransomware Dharma Past Underground (report)