Phoenix Locker
- First seen
- 2022-03-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:03:11
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality
Context
Phoenix Locker is a ransomware family that encrypts files on infected systems and demands a ransom for decryption keys. It has been used in attacks against various industries including financial services, healthcare, and retail.
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- services.google.com — Threat Horizons Report H1 2025 (report)
- killingthebear.jorgetesta.tech — Evil Corp (report)
- Mandiant — Unc2165 Shifts To Evade Sanctions (report)
- assets.sentinelone.com — Sentinellabs Evilcorp (report)
- sentinelone.com — S1 Sentinellabs Sanctionsbedamned Final 02 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Phoenix Locker (report)