Phobos Ransomware Group
| Actor Type | Criminal Group |
|---|
According to public reporting, Phobos ransomware has been observed since at least 2019, with researchers also linking the group to the Dharma ransomware. Reporting suggests that the group uses a Ransomware-as-a-Service (RAAS) model, with affiliates responsible for deploying the ransomware in victim environments.
Victims of Phobos have included local and regional government, public services, healthcare and critical infrastructure.
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph
Phobos Ransomware Group Threat Reports
Report
StopRansomware: Phobos Ransomware
This is a joint Cybersecurity Advisory produced by CISA, the FBI and the Multi-State Information Sharing and Analysis Center (MS-ISAC). It ...
References
malpedia.caad.fkie.fraunhofer.de
https://malpedia.caad.fkie.fraunhofer.de/details/win.phoboswww.cisa.gov
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060awww.lemonde.fr
https://www.lemonde.fr/en/pixels/article/2023/11/10/phobos-ransomware-two-russians-arrested-following-a-dozen-attacks-in-france_6244594_13.htmlwww.malwarebytes.com
https://www.malwarebytes.com/blog/news/2019/07/a-deep-dive-into-phobos-ransomwareblog.talosintelligence.com
https://blog.talosintelligence.com/deep-dive-into-phobos-ransomware/blog.talosintelligence.com
https://blog.talosintelligence.com/understanding-the-phobos-affiliate-structure/MITRE ATT&CK Techniques
MITRE ATT&CK techniques observed in use by this intrusion set.