Phoenix

First seen
2019-10-01 00:00:00
Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-18 22:16:35
Profile updated
2026-07-07 14:08:47

Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector

Targeted regions: country_code:us country_code:ca country_code:uk

Context

Phoenix ransomware is known for targeting organizations in financial services, healthcare, and government sectors across North America and the UK. It encrypts files and demands a ransom for recovery, often disrupting operations by impacting critical infrastructure.

Detection coverage

  • 4 YARA rules

Detection rules

  • MALPEDIA_Win_Phoenix_Locker_Auto (yara-rule)
  • ARKBIRD_SOLG_MAL_Phoenix_Stealer_Jun_2021_1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Phoenix (yara-rule)
  • SEKOIA_Infostealer_Win_Phoenix (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Phoenix (report)
  • cryptax.medium.com — Reverse Engineering Of Android Phoenix B59693C03Bd3 (report)

External references