FILEMembers
FILE

Phorpiex Drop Point Holds Steady as Yemeni Telecom ASN Absorbs New Churn

A long-running Phorpiex/Kadrbot delivery cluster shows its core infrastructure untouched: the same bare-IP host still serves six sequential /twizt/ paths. What changed is peripheral only — three newly logged IPs, two sharing a Yemeni state-telecom ASN, replace five that dropped out.

Sep 17, 2026, 14:29 (UTC+9)Last seenSep 17, 2026Severity100ByCTX TeamIOC15MITRE37RegionsAFRO

The most interesting fact in this snapshot of a long-running Phorpiex/Kadrbot cluster isn't a new payload — it's what didn't change. The bare-IP delivery host that anchored CTX Team's earlier look at this cluster, 185.215.113.84, still serves the same six sequentially numbered /twizt/1 through /twizt/6 paths it did before, sitting at 16 of 89 security-vendor detections on VirusTotal.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence