typeentityfamilyphorpiexconfidencemediumcreated2026-06-02updated2026-09-05malware-familyloadermalware-bazaarattribution

Phorpiex

A crimeware botnet/dropper family active since at least 2016. Known to distribute ransomware, cryptocurrency miners, and other commodity payloads via spam campaigns. The label originates from MalwareBazaar/OpenCTI where multiple samples are tagged dropped-by-phorpiex. The family label itself is an umbrella: samples vary widely in size (10–300 KB), build toolchain, and payload (static-only analysis shows this is not a single-codebase cluster).

Observed Build Patterns

  • MSVC C++ x32 stubs linked statically against MSVCR90.dll, mimicking Microsoft Screen Saver binaries ^[/intel/analyses/755bed077773b6cc7bea81ff624ded0554784accd5745d734742dafb73833b6b.html]
  • Go droppers with packed UPX overlays (observed in sibling dropped-by-phorpiex samples)
  • Minimal IAT — only a handful of KERNEL32 and MSVCR90 imports; actual payload imported via runtime resolution or reflective injection

Observed Deploy / ATT&CK

  • T1204.002 — User Execution: Malicious File — spam-distributed PEs with social-engineered names
  • T1053 — Scheduled Task/Job (inferred from historical reporting for Phorpiex)
  • Payload delivery mechanism: runtime-decoded shellcode or PE via phorpiex-loader-initterm-hijack ^[/intel/analyses/755bed077773b6cc7bea81ff624ded0554784accd5745d734742dafb73833b6b.html]
  • New variant: cplapplet-png-payload-dropper — x64 CPlApplet that expects a payload.png companion file, decrypts/decompresses a second-stage DLL, self-erases, and executes. May 2026 build.

Capabilities

  • parasitic-pe-section-append (new — .zero section, entry-point patch, ImageBase=0xdead sentinel)
  • peb-walking-api-hash-resolution (new — custom hash constants, export-name iteration)
  • shellcode-ntdll-scratchpad-copy (new — intermediate RX copy before victim write)
  • twiztpeinf-mutex-gating
  • windrx-marker-file
  • nodrives-registry-evasion
  • drive-blacklist-skip
  • initterm-hijack-payload-decoder
  • thin-msvc9-downloader
  • dual-fetch-wininet-urlmon
  • zone-identifier-ads-deletion
  • rtlgversion-build-gating
  • marker-file-mutex-gating
  • temp-random-filename-staging
  • x64-progfiles-check
  • chrome-128-ua-masquerade
  • peinf-xmr-xmrget-grab-payload-chain
  • http-cleartext-c2
  • anti-debug-isdebuggerpresent
  • iat-minimization-runtime-api-resolution
  • screensaver-masquerade
  • msvcr90-static-crt
  • zip-header-manual-assembly
  • smtp-self-spoofing
  • http-chrome-ua-downloader
  • sexttortion-email-template
  • bitcoin-wallet-hardcoded
  • thread-storm-spam-delivery
  • xor-not-string-decryption
  • dns-mx-resolution
  • mime-multipart-zip-attachment
  • external-ip-http-check
  • temp-file-spam-staging
  • zone-identifier-deletion
  • mutex-single-instance
  • cplapplet-png-payload-dropper (new x64 variant, May 2026)
  • api-name-xor-decryption
  • custom-byte-pair-decompression
  • self-text-erasure
  • gettickcount-anti-emulation-loop
  • marker-file-mutex-gating
  • wininet-urlmon-dual-download
  • createprocessw-create_no_window
  • rtlgversion-build-gating
  • x64-arch-check-progfiles-x86
  • sextortion-500-usd-variant (May 2026; earliest cluster build)
  • sextortion-1200-usd-variant (May 2026; standard cluster build)
  • sextortion-800-usd-variant (May 2026; sibling of 1200 variant, updated Chrome UA, mutex etyueu)
  • gettickcount-anti-emulation-loop
  • 13-14-peinf-xmr-xmrget-payload-chain (earliest campaign build, May 2026)
  • business-app-masquerade-execution (new May 2026 variant: Slack, Teams, Zoom, SAP GUI, Power BI, Tableau)
  • ip-api-geolocation-gating
  • country-code-cn-exclusion
  • zone-identifier-ads-deletion
  • chrome-7775543322-ua-masquerade
  • dual-ua-rotation-chrome-plausible-fallback (new — e50d0e5a adds Chrome/93.0.4577.82 alongside the impossible-version UA)
  • business-app-masquerade-expanded-url-list (new — e50d0e5a carries 31 payload URLs vs 11 in 0371fbbf)
  • sextortion-800-usd-variant-mutex-t4 (new — dc2936ea, twin build of c3b1b4e4, mutex t4, compiled 44 seconds earlier, same campaign burst)
  • sextortion-800-usd-variant-mutex-t5 (new — c3b1b4e4, mutex t5, identical SMTP engine and decrypt key Tmlr, 5,000-thread dispatch, yahoo.com MX query, self-contained WinInet+WS2_32 spam bot)
  • sextortion-800-usd-variant-mutex-t6 (new — 3bfbfb35, mutex t6, compiled 12:34:48 UTC May 29, between t5 (12:34:02) and t7 (12:36:22), same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window title YOU PERVERT! I RECORDED YOU!. Fills the ~1m46s gap, confirming sub-minute builder rotation.)
  • sextortion-800-usd-variant-mutex-t13 (new — 04134145, mutex t13, compiled 12:42:51 UTC, ~8 minutes after t5; adds window-title string YOU PERVERT! I RECORDED YOU!, same Tmlr key, same BTC wallet, same 5,000-thread SMTP engine. Confirms active builder parameter rotation across t1–t13 in a ~30-minute campaign burst.)
  • sextortion-800-usd-variant-mutex-t2 (new — 5076fdc3, mutex t2, earliest confirmed build in $800 sub-cluster at 12:15:01 UTC, predates t4/t5 twins by ~18 minutes, identical decrypt key and BTC wallet)
  • sextortion-800-usd-variant-mutex-t1 (new — 67ae1ba4, mutex t1, earliest build in the $800 campaign burst at 12:13:57 UTC, predates t2 by ~1 minute; adds window title string YOU PERVERT! I RECORDED YOU!)
  • sextortion-800-usd-variant-mutex-t7 (new — 49740d89, mutex t7, compiled 12:36:22 UTC, ~22 minutes after t1 build, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window title YOU PERVERT! I RECORDED YOU!)
  • sextortion-800-usd-variant-mutex-t12 (new — b221a625, mutex t12, compiled 12:41:46 UTC May 29, fills gap between t7 and t13, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window title YOU PERVERT! I RECORDED YOU!)
  • sextortion-800-usd-variant-mutex-t11 (new — cbc59001, mutex t11, compiled 12:40:35 UTC May 29, between t7 (12:36:22) and t12 (12:41:46), same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window title YOU PERVERT! I RECORDED YOU!)
  • sextortion-800-usd-variant-mutex-t10 (new — 724ec6b8, mutex t10, compiled 12:39:58 UTC May 29, between t7 (12:36:22) and t11 (12:40:35), same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window title YOU PERVERT! I RECORDED YOU!. Fills the ~3.5-minute gap in the campaign burst, confirming continuous builder rotation.)
  • sextortion-800-usd-variant-mutex-t9 (new — 8f257c0e, mutex t9, compiled 12:37:51 UTC May 29, between t7 (12:36:22) and t10 (12:39:58), same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window title YOU PERVERT! I RECORDED YOU!. Fills the ~1.5-minute gap between t7 and t10, confirming continuous builder rotation.)
  • sextortion-800-usd-variant-mutex-523535 (new — bb0a8440, mutex 523535, compiled 12:02:34 UTC May 29, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine, window title YOU PERVERT! I RECORDED YOU!. Delta: new Chrome/202.0.4664.110 UA (prior siblings used Chrome/128 or Chrome/7775543322), numeric mutex breaks the t* naming pattern observed in t1–t13 sub-cluster)
  • sequential-1-12-payload-naming (new — ee83f1e8, thin downloader with 1.exe–12.exe sequential naming, replacing lb* convention)
  • rtlgetversion-windows11-build-gate (new — ee83f1e8, gates xmrget.exe on build >= 22000, first thin-downloader sibling with this gate)
  • thin-downloader-15-payload (confirmed — ee83f1e8, 15 URLs: 1.exe–12.exe, xmr.exe, xmrget.exe, grab.exe)

Notable Analyses

  1. x32 MSVC9 stub / MSVCR90 dropper (e.g. 755bed07) — 21 KB, pre-main payload through initterm, masquerades as Microsoft Screen Saver

  2. Go/UPX droppers (siblings in corpus) — much larger, UPX-packed

  3. Sextortion spam bot — $500 variant (bb77ef06) — 19 KB, earliest May-22 campaign build (13:05 UTC), mutex efaefaef, hardcoded BTC 1NXeVuYtcVwJ1do2EUS6qJS8FQSPFabxeE, Chrome/202 UA, $500 ransom demand. Precedes the $1200 builds by ~4 hours. ^[/intel/analyses/bb77ef06de83dc5e450572c04f69224c44786bda5eadc9e7a698dc4ef1445edf.html]

  4. Sextortion spam bot — $1200 variant (e.g. 150e4652) — 23 KB, self-contained SMTP engine + ZIP constructor + hardcoded BTC wallet

  5. Sextortion spam bot sibling (e.g. 17960bcb) — 24 KB, same build day, identical payload architecture, mutex ww88ww8w8

  6. Sextortion spam bot — $800 variant (edd6ad22) — 18.9 KB, compiled 2026-05-26 06:02:43 UTC, same SMTP engine and BTC wallet as 150e4652. Delta: $800 demand (vs $1200), Chrome/202 UA, mutex etyueu. Confirms campaign-parameter rotation across builds. ^[/intel/analyses/edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19.html]

  7. Thin HTTP downloader (6b8527a7) — 10 KB, MSVC9, dual WinInet+URLMon fetch, marker-file gating, Zone.Identifier deletion, x64+build gating for xmr.exe/xmrget.exe. No initterm hijack; honest main() flow. 2026-05-22 16:56 UTC

  8. Thin HTTP downloader sibling (025f5798) — 10 KB, confirmed campaign sibling compiled 3h51m earlier (2026-05-22 13:06 UTC). Same C2 (178.16.54.109), same gating, same dual-fetch. Delta: omits 15.exe payload present in later build.

  9. Thin HTTP downloader sibling — peinf/xmr/xmrget chain (2ffc3203) — 10 KB, compiled 2026-05-22 07:45:34 UTC. Same C2, same gating, same dual-fetch. Delta: payload name rotation — peinf.exe replaces 15.exe; adds third-stage xmrget.exe. Confirms active C2 payload rotation within the same campaign window.

  10. Earliest thin HTTP downloader sibling (32f29422) — 10 KB, compiled 2026-05-22 06:19:01 UTC. Same C2, same gating, same dual-fetch. Delta: earliest build; adds grab.exe as fallback payload when the primary peinf/xmr/xmrget chain fails. Honest main() flow; no initterm hijack.

  11. Ultra-early thin HTTP downloader sibling — 13/14 chain (f67e429d) — 10 KB, compiled 2026-05-21 23:03:35 UTC. Earliest known build in the campaign window, predating 32f29422 by ~7 hours. Same C2, same toolchain. Deltas: five payload URLs (13.exe, 14.exe, peinf.exe, xmr.exe, xmrget.exe); dual filesystem marker gates (d333...txt and f3f3...txt); both RtlGetVersion and x64 Program-Files checks present.

  12. Thin HTTP downloader sibling — 15-payload variant (5549d978e2e0) — 11.8 KB, compiled 2026-05-26 10:32:54 UTC. Same C2 (178.16.54.109), same MSVC9 toolchain, same dual-fetch gating. Delta: largest payload list in campaign (15 URLs: 1.exe–14.exe, peinf.exe, xmr.exe, xmrget.exe, grab.exe); no 15.exe observed. Confirms active payload rotation within the campaign window. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/5549d978e2e00768fc99d95bd7644dfebacc261284e3b19a79e6e4c1f320fa3a.html]

  13. Business-app masquerade downloader (9570038453) — 113 KB, compiled 2026-05-26 07:35:20 UTC. Largest downloader in the campaign (~10× the thin stubs). C++ STL bloat, WinInet-only (no URLMon fallback observed), ip-api.com/json geolocation gating with explicit CN exclusion, %TEMP%\w4f4wffwf.txt marker-file gate, random-numeric filename staging (%d%d.exe), Zone.Identifier ADS deletion, and six hardcoded masquerade names (slack.exe, Teams.exe, Zoom.exe, sapgui.exe, PBIDesktop.exe, tableau.exe) passed to ShellExecuteW. Fake UA: Chrome/7775543322.0.0.0. Same C2 (178.16.54.109) as thin-downloader cluster. ^[/intel/analyses/9570038453a8b3caa9e7a0af56ef77cee9cfb314c357e62f4350fb99f6afc51f.html]

  14. Business-app masquerade downloader sibling (0371fbbf) — 113 KB, compiled 2026-05-29 10:10:01 UTC. Confirmed third business-app masquerade sibling (same size, same toolchain, same six masquerade names, same w4f4wffwf.txt gate, same CN geolocation exclusion). Deltas: adds lkdomain.exe as a primary payload URL and ten sequentially-named payloads (lb1.exe–lb10.exe), blending the business-app masquerade pattern with the thin-downloader lb* payload-naming convention. Same fake UA (Chrome/7775543322.0.0.0). Same C2 (178.16.54.109). Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/0371fbbff34ec41ee9ae007482edbcb75f1749661b863da3a2ffe86638cd62a3.html]

  15. Parasitic file infector — TWIZTPEINF variant (d69d4497) — 22 KB, compiled 2026-05-29 11:32:30 UTC. First parasitic infector observed in the campaign. Appends a .zero section to every *.exe on visible drives, patches entry point, sets ImageBase=0xdead infection sentinel. Payload shellcode uses PEB-walking API hash resolution (fcn.00401bc0) and downloads stage-2 via URLDownloadToFileW. Mutex TWIZTPEINF, marker file %appdata%\windrx.txt, registry NoDrives gating. Sibling e0de4e3c... is a byte-identical twin (same binary, different OpenCTI artifact ID). Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/d69d4497aa86ebf8e32ed15ecb21a3bf37aefdd23e517646680d62a718772647.html]

  16. Parasitic file infector twin (e0de4e3c) — byte-identical to d69d4497; same TWIZTPEINF marker, same C2 (178.16.54.109/32.exe), same build fingerprint. Confirms OpenCTI pipeline ingested the same sample twice under distinct artifact records. Static-only. ^[/intel/analyses/e0de4e3c9dee9877c78832ac9ebe3fbd2de45026896d6fc2a5ca12f6b588a29a.html]

  17. Business-app masquerade downloader — expanded payload list (e50d0e5a) — 114 KB, compiled 2026-05-29 11:37:19 UTC. Fourth confirmed business-app masquerade sibling. Same six masquerade names, same w4f4wffwf.txt gate, same CN geolocation exclusion, same fake UA (Chrome/7775543322.0.0.0). Deltas: expands payload URL list from 11 to 31 (lkdomain.exe + lb1.exe–lb30.exe); adds a second fake UA (Chrome/93.0.4577.82); drops f3f3g3df.txt / NoDrives / OUTLOOKFOUND indicators seen in 0371fbbf. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/e50d0e5abf23d4cdb1021c0db51572a785150f0a797fbe57b203b54c26c086e1.html]

  18. Sextortion spam bot — $800 variant, mutex t5 (c3b1b4e4) — 18.9 KB, compiled 2026-05-29 12:34:02 UTC. Fifth confirmed sextortion sibling in the $800 sub-cluster (preceded by edd6ad22). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine + ZIP-less email body, same Tmlr XOR+NOT decrypt key. Deltas: mutex t5 (new), BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, thread count 5,000 (highest in cluster), no ZIP attachment. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html]

  19. Sextortion spam bot — $800 variant, mutex t4 (twin of t5) (dc2936ea) — 18.9 KB, compiled 2026-05-29 12:33:18 UTC. Twin build of c3b1b4e4, compiled 44 seconds earlier in the same campaign burst. Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine + ZIP-less email body, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutex t4 (vs t5). Confirms campaign-level parameter rotation, not code change. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a.html]

  20. Sextortion spam bot — $800 variant, mutex t2 (earliest confirmed build) (5076fdc3) — 18.9 KB, compiled 2026-05-29 12:15:01 UTC. Earliest confirmed build in the $800 sub-cluster, predating t4/t5 twins by ~18 minutes. Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutex t2 (new). Confirms the builder was generating mutex-rotated variants in a continuous campaign burst. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/5076fdc39445369e67daaccb7ec1699107a5f227aaaec978ec9d77d966124f3d.html]

  21. Sextortion spam bot — $800 variant, mutex t1 (earliest build in burst) (67ae1ba4) — 18.9 KB, compiled 2026-05-29 12:13:57 UTC. Predates the t2 build by ~1 minute, making it the earliest confirmed build in the $800 campaign burst. Same MSVC9/MSVCR90 toolchain, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread SMTP engine. Delta: mutex t1 (new); adds window title string YOU PERVERT! I RECORDED YOU! not seen in prior siblings. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/67ae1ba4090ec9277beb8bdc56379716cc59054d9a5151886cc91838eed217b9.html]

  22. Thin HTTP downloader — 15-payload sequential naming variant (ee83f1e8) — 11 KB, compiled 2026-05-29 12:16:54 UTC. New thin-downloader morph: sequential 1.exe–12.exe payload naming (replacing lb* and peinf conventions); same dual WinInet+URLMon fetch, same d333...txt / f3f3...txt marker-file gating, same Zone.Identifier ADS deletion, same Chrome/128.0.0.0 fake UA. Delta: adds RtlGetVersion Windows 11 build gate (build >= 22000) for xmrget.exe fetch — first thin-downloader sibling with this gate. Same C2 (178.16.54.109). Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/ee83f1e835ae321ac303708151a85bdf35ff64b09eb706458e901bc77d40c83c.html]

  23. Sextortion spam bot — $800 variant, mutex t13 (sixth confirmed $800 sibling) (04134145) — 18.9 KB, compiled 2026-05-29 12:42:51 UTC. Sixth confirmed sibling in the $800 sub-cluster (preceded by t1–t5). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine + ZIP-less email body, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Deltas: mutex t13 (new); adds window title string YOU PERVERT! I RECORDED YOU! (also seen in t1); compiled ~8 minutes after t5, confirming active builder parameter rotation across a ~30-minute campaign burst. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/041341453321adb6bceb73abee88484a28f27f0de1e2916575cdbc197ea839dc.html]

  24. Sextortion spam bot — $800 variant, mutex t7 (seventh confirmed $800 sibling) (49740d89) — 18.9 KB, compiled 2026-05-29 12:36:22 UTC. Seventh confirmed sibling in the $800 sub-cluster (between t5 and t13). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutex t7 (new); window title YOU PERVERT! I RECORDED YOU!. Compiled ~22 minutes after the t1 earliest build, fitting the continuous campaign burst timeline. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031.html]

  25. Sextortion spam bot — $800 variant, mutex t12 (eighth confirmed $800 sibling) (b221a625) — 18.9 KB, compiled 2026-05-29 12:41:46 UTC. Eighth confirmed sibling in the $800 sub-cluster, between t7 (12:36:22) and t13 (12:42:51). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutex t12 (new); fills the ~7-minute gap between t7 and t13, confirming continuous builder rotation. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95.html]

  26. Sextortion spam bot — $800 variant, mutex t11 (ninth confirmed $800 sibling) (cbc59001) — 18.9 KB, compiled 2026-05-29 12:40:35 UTC. Ninth confirmed sibling in the $800 sub-cluster, between t7 (12:36:22) and t12 (12:41:46). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutex t11 (new); compiled ~4 minutes after t7, confirming continuous builder rotation. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000.html]

  27. Sextortion spam bot — $800 variant, mutex t9 (tenth confirmed $800 sibling) (8f257c0e) — 18.9 KB, compiled 2026-05-29 12:37:51 UTC. Tenth confirmed sibling in the $800 sub-cluster, between t7 (12:36:22) and t10 (12:39:58). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutex t9 (new); fills the ~1.5-minute gap between t7 and t10, confirming continuous builder rotation. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c.html]

  28. Sextortion spam bot — $800 variant, mutex t8 (eleventh confirmed $800 sibling) (cff535e6) — 18.9 KB, compiled 2026-05-29 12:37:13 UTC. Eleventh confirmed sibling in the $800 sub-cluster, between t7 (12:36:22) and t9 (12:37:51). Same MSVC9/MSVCR90 toolchain, same self-contained SMTP engine, same Tmlr XOR+NOT decrypt key, same BTC wallet 1Gpu4hxcqpLZyjQ4JHZ6ieojyVBFj81Y3K, same 5,000-thread dispatch. Delta: mutex t8 (new); fills the ~51-second gap between t7 and t9, confirming continuous builder rotation at sub-minute granularity. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556.html]

Notes

No deep-analysis report existed for any dropped-by-phorpiex sample in the corpus prior to this one. The label aggregates disparate builders under a single campaign umbrella. Individual samples should be characterized by their actual build/behavior rather than by the umbrella label alone.

Related Analyses

  • /intel/analyses/c3b1b4e4eab9589b9132c57cc6dc9f26b93fee922b78923780cb79ce705f106b.html — sextortion spam bot $800 variant, mutex t5, 5,000 threads
  • /intel/analyses/dc2936ea921e2cbc56b315d1c08d2c3e1ce4f4e22524c9bdee12a8ea2e037e5a.html — sextortion spam bot $800 variant, mutex t4 (twin build, 44 seconds earlier), 5,000 threads
  • /intel/analyses/150e46523ae4a3e90ce949f15630b2f07d475d3a781188301edded1d527f03af.html — sextortion spam bot with SMTP engine, ZIP constructor, and hardcoded BTC wallet
  • /intel/analyses/755bed077773b6cc7bea81ff624ded0554784accd5745d734742dafb73833b6b.html — screensaver masquerade stub with .rsrc payload staging
  • /intel/analyses/17960bcb0d7fe57fac3a286fe7e8ba9b53783fdd53a2ef1132ae4d302d2c18f3.html — sextortion spam bot sibling (same build timestamp)
  • /intel/analyses/edd6ad227595d25c2cf6cf41d2ac9b6640b2e977aabb2d07eea58fa500b6db19.html — sextortion spam bot $800 variant (mutex etyueu)
  • /intel/analyses/49740d891262803c8b246275ac6a80bb64ee2c3fb76953b3f365f5b236105031.html — sextortion spam bot $800 variant, mutex t7, 12:36:22 UTC
  • /intel/analyses/b221a625be886002e3a18c1302bf5a564d45b706eac539d9d04494cffbedbd95.html — sextortion spam bot $800 variant, mutex t12, 12:41:46 UTC
  • /intel/analyses/bb0a84401c30c261c5e4d2f28b8e9ccea9742c586c254c10625c50a57000eb49.html — sextortion spam bot $800 variant, mutex 523535, numeric mutex breaking t* pattern
  • /intel/analyses/cbc590012eba8834dd1a984de7b17e92bdf616d06be1f622c42b41ab73844000.html — sextortion spam bot $800 variant, mutex t11, 12:40:35 UTC
  • /intel/analyses/8f257c0e8cea430559676f2f30d96a90c8bbdf54041314e3960750421b66e29c.html — sextortion spam bot $800 variant, mutex t9, 12:37:51 UTC
  • /intel/analyses/cff535e6dfde92026a6bb293423e472d8a5bc24732dd3034c1fe54118a395556.html — sextortion spam bot $800 variant, mutex t8, 12:37:13 UTC
  • /intel/analyses/724ec6b8d24acad8b84cc87b7f77a8d2cf25e3a6d1d1dcadbd0b94b5ef9d8a8f.html — sextortion spam bot $800 variant, mutex t10, 12:39:58 UTC
  • /intel/analyses/ee83f1e835ae321ac303708151a85bdf35ff64b09eb706458e901bc77d40c83c.html — thin downloader, sequential payload naming, RtlGetVersion Windows 11 gate