Phoenix Locker

First seen
2022-03-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 13:03:11

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

Phoenix Locker is a ransomware family that encrypts files on infected systems and demands a ransom for decryption keys. It has been used in attacks against various industries including financial services, healthcare, and retail.

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • services.google.com — Threat Horizons Report H1 2025 (report)
  • killingthebear.jorgetesta.tech — Evil Corp (report)
  • Mandiant — Unc2165 Shifts To Evade Sanctions (report)
  • assets.sentinelone.com — Sentinellabs Evilcorp (report)
  • sentinelone.com — S1 Sentinellabs Sanctionsbedamned Final 02 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Phoenix Locker (report)

External references