Cyber Threat Report: 'StopRansomware: Phobos Ransomware'

Report Author CISA
Publication Date 2024-02-29
Original Reporting Source
Related Intrusion Sets Phobos Ransomware Group
Victim Sectors Emergency Services, Education, Healthcare, Local Government, Regional Govenment

This is a joint Cybersecurity Advisory produced by CISA, the FBI and the Multi-State Information Sharing and Analysis Center (MS-ISAC). It outlines tactics, techniques and procedures associated with the Phobos ransomware. Phobos ransomware operates as 'Ransomware-as-a-Service' with victims observed up to February 2024 (the time of publication). The advisory states that Phobos is often deployed alongside other tools including Smokeloader, Cobalt Strike, and Bloodhound.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques