Phoenix
- First seen
- 2019-10-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-18 22:16:35
- Profile updated
- 2026-07-07 14:08:47
Targeted industries: financial-services healthcare-and-pharmaceutical government-and-public-sector
Targeted regions: country_code:us country_code:ca country_code:uk
Context
Phoenix ransomware is known for targeting organizations in financial services, healthcare, and government sectors across North America and the UK. It encrypts files and demands a ransom for recovery, often disrupting operations by impacting critical infrastructure.
Detection coverage
- 4 YARA rules
Detection rules
- MALPEDIA_Win_Phoenix_Locker_Auto (yara-rule)
- ARKBIRD_SOLG_MAL_Phoenix_Stealer_Jun_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Phoenix (yara-rule)
- SEKOIA_Infostealer_Win_Phoenix (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Apk.Phoenix (report)
- cryptax.medium.com — Reverse Engineering Of Android Phoenix B59693C03Bd3 (report)