RIP (Phoenix) Ransomware

Aliases: RIP, Phoenix

Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-18 22:16:35
Profile updated
2026-07-07 13:29:47

Context

It’s directed to English speaking users, therefore is able to infect worldwide. It is spread using email spam, fake updates, attachments and so on. It encrypts all your files, including: music, MS Office, Open Office, pictures, videos, shared online files etc.. Based on HiddenTear

Detection coverage

  • 4 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Phoenix_Stealer_Jun_2021_1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Phoenix (yara-rule)
  • SEKOIA_Infostealer_Win_Phoenix (yara-rule)
  • MALPEDIA_Win_Phoenix_Locker_Auto (yara-rule)

Reports & references

  • id-ransomware.blogspot.co.il — Rip Ransomware (report)
  • twitter.com — 804810315456200704 (report)

External references