Phobos Ransomware

Description Summary

Phobos is a long-running ransomware-as-a-service first observed in 2019, derived from the Crysis/Dharma lineage. It is favored by lower-tier affiliates targeting small and mid-sized organizations and SLTT governments, typically via brute-forced or phishing-obtained RDP access. Phobos underpins numerous rebrands/variants (8base, Eight, Devos, Faust, Elking, BackMyData). It is the subject of CISA advisory AA24-060A; an international operation (Phobos Aetor) disrupted the operation and 8base in February 2025.

Threat Actor

RaaS (Crysis/Dharma lineage); many affiliates and rebrands. Core operators disrupted in February 2025 (Operation Phobos Aetor).

Technical Indicators

Encryption Extension
.id[<ID>].[<email>].phobos (also .eight, .devos, .faust, .8base, etc.)
Encryption Algorithm
AES-256 (files) + RSA-1024 (hardcoded key)
Ransom Note Name
info.txt / info.hta
Targeted Industries
SLTT government, Healthcare, Education, SMB cross-sector
First Seen
May 2019
Last Seen
Active; core infrastructure seized February 2025
Geographical Location
Worldwide

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1133 External Remote Services (RDP)
T1078 Valid Accounts
Credential Access x 1 T1110 Brute Force
Defense Evasion x 1 T1562.001 Disable or Modify Tools
Impact x 3 T1490 Inhibit System Recovery
T1486 Data Encrypted for Impact
T1489 Service Stop