
Phorpiex Botnet Adds Kernel Driver and Go Wallet Stealer in 2026 Upgrade
A Phorpiex campaign active since June 2026 has added a Bring-Your-Own-Vulnerable-Driver kernel component and a Go-runtime cryptocurrency wallet infostealer to its traditional spam-and-mine playbook. The dual-monetisation operation — harvesting both compute power and browser-extension wallet credentials — runs through four C2 IPs in a Seychelles-registered autonomous system with a structured versioned API for domain rotation. CTX Team rates the cluster at severity 100 with medium confidence, flagging it as a meaningful escalation for a family historically associated with commodity botnet activity.
A Phorpiex botnet campaign active since early June 2026 has added two capabilities that sit well outside the family's historical playbook: a Bring-Your-Own-Vulnerable-Driver kernel component and a Go-runtime infostealer purpose-built to drain cryptocurrency wallet browser extensions. The combination — mass SMTP propagation, XOR-obfuscated PE droppers, XMRig cryptomining, kernel-driver abuse, and browser-extension credential harvesting, all consolidated on four command-and-control IPs inside a…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read