Description Summary
Phobos is a long-running ransomware-as-a-service first observed in 2019, derived from the Crysis/Dharma lineage. It is favored by lower-tier affiliates targeting small and mid-sized organizations and SLTT governments, typically via brute-forced or phishing-obtained RDP access. Phobos underpins numerous rebrands/variants (8base, Eight, Devos, Faust, Elking, BackMyData). It is the subject of CISA advisory AA24-060A; an international operation (Phobos Aetor) disrupted the operation and 8base in February 2025.
Threat Actor
RaaS (Crysis/Dharma lineage); many affiliates and rebrands. Core operators disrupted in February 2025 (Operation Phobos Aetor).
Technical Indicators
Encryption Extension
.id[<ID>].[<email>].phobos (also .eight, .devos, .faust, .8base, etc.)
Encryption Algorithm
AES-256 (files) + RSA-1024 (hardcoded key)
Ransom Note Name
info.txt / info.hta
Targeted Industries
SLTT government, Healthcare, Education, SMB cross-sector
First Seen
May 2019
Last Seen
Active; core infrastructure seized February 2025
Geographical Location
Worldwide
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1133 | External Remote Services (RDP) | |
| T1078 | Valid Accounts | |
| Credential Access x 1 | T1110 | Brute Force |
| Defense Evasion x 1 | T1562.001 | Disable or Modify Tools |
| Impact x 3 | T1490 | Inhibit System Recovery |
| T1486 | Data Encrypted for Impact | |
| T1489 | Service Stop |