Phorpiex malware family
Phorpiex is a malware family tracked by MalwareAnalyzer by Cyble across 15 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-02. Observed ATT&CK techniques include T1071.001, T1112, T1543.003.
Corpus statistics
- Publicly analyzed samples: 15
- First seen: 2026-07-28
- Last seen: 2026-08-02
- Verdicts: malicious 15
- File types: pe 15
ATT&CK techniques used by Phorpiex
Extracted command-and-control infrastructure
- http://www.binance.com - 5 samples
- http://www.bitrefill.com - 5 samples
- http://www.coinbase.com - 5 samples
- http://www.crypto.com - 5 samples
- http://www.etoro.com - 5 samples
- https://trustcard4you.com - 4 samples
- 178.16.54.109 - 2 samples
- http://178.16.54.109/v.exe - 1 sample
- https://bestmeds4you.com - 1 sample
- https://tw-card.sbs/ - 1 sample
Recent Phorpiex samples
- 1ccfd6555390617b416bed0bd48ef3edba47bf042e102f504a2113bc356eeb0f.exe - malicious (2026-08-02)
- 30793394a8638778432c95d8c121b00f7a4c64226588d1a5d2538bd62f3b187b.exe - malicious (2026-07-31)
- 405904c8a9ec04b73ac95b7e43a4c9c567b526d178257b56e4a8d812f478ddc3.exe - malicious (2026-07-31)
- 30cf8b82a53fff20b564597e56123ddeb16a87441a8b94f621e52c3213aeaa2c.exe - malicious (2026-07-31)
- 1945428f1a5bcac0595556d7acba0802c96ef9d9552a91c77d71f7bfd89c22f4.exe - malicious (2026-07-31)
- 0ecc8ca00c5f331e2bb732b2295c8e019592d333c2ae0270653bc2900384a700.exe - malicious (2026-07-31)
- 4ddf530a9ced8cb042c88e3fdd75933a08cd1419a1f3bbd7a3e6b8f3e6b6260d.exe - malicious (2026-07-29)
- 3fe19e12a6c3054ca089010c5da14867a4e7ccbd72560dcbe8cdc99f44e36f48.exe - malicious (2026-07-29)
- 324a60acad30f9940a829594943d9e7a33ad1c32989b35ff6545e5a2df759be6.exe - malicious (2026-07-29)
- c7dc544ed14e75219a4eb0b02690d47e412f615f2f1329f99a00337a72b17256.exe - malicious (2026-07-28)
- 99eae3c904882be5ffe456421a80ffcdfcfd743958ebdbf83c4e46a7bc3f525a.exe - malicious (2026-07-28)
- 5414c823040b85495f88add29911ec42836277d9b1732468f70c29140cb198be.exe - malicious (2026-07-28)
- 2fed5d0552cf80eaae1928150238397a632ebb9521e98129daa71eb46ea1f113.exe - malicious (2026-07-28)
- 2cf0bc8361e716ffb2dbfa4c680028bf6b2dcbcd84a14c511dfec0af523860c8.exe - malicious (2026-07-28)
- 09b7fa9a1bc1c3f34bcca306c1f9e3971083ebf265adf5f7684e4a320b5d562e.exe - malicious (2026-07-28)
Frequently asked about Phorpiex
- What is Phorpiex?
- Phorpiex is a malware family tracked by MalwareAnalyzer by Cyble across 15 publicly analyzed samples. First seen 2026-07-28, most recently 2026-08-02. Observed ATT&CK techniques include T1071.001, T1112, T1543.003.
- How many Phorpiex samples have been analyzed?
- MalwareAnalyzer by Cyble holds 15 publicly analyzed samples attributed to Phorpiex, first seen 2026-07-28 and most recently 2026-08-02. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Phorpiex use?
- Across our Phorpiex samples the most frequently observed techniques are T1071.001 (15), T1112 (12), T1543.003 (2). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Phorpiex use?
- Phorpiex samples in this corpus are distributed as pe (15).
- Does Phorpiex use command-and-control infrastructure?
- Yes. 10 distinct command-and-control indicators have been extracted from Phorpiex samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Phorpiex malicious?
- 15 of 15 analyzed Phorpiex samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends