C&CMembers
C&C

Phorpiex Rotates All Payloads Again as C2 Holds Firm for Ninth Wave

All three payload files in the latest Phorpiex/Trik snapshot are new arrivals, two carrying zero VirusTotal metadata — while the campaign's two C2 IPs and four tsrv2.top URL paths remain unchanged. The operator's disciplined binary-churn strategy, combined with long-sleep sandbox evasion and svchost masquerading, continues to target telecommunications operators in Kazakhstan and Pakistan.

Jun 17, 2026, 20:27 (UTC+9)Last seenJun 25, 2026Severity100ByCTX TeamIOC9MITRE35RegionsKZPK

##Phorpiex Swaps Its Entire Payload Stack — Again — While C2 Holds Firm for a Ninth Consecutive Wave Since earlier coverage documented the Phorpiex/Trik operator's discipline of rotating binaries while leaving command-and-control infrastructure untouched, that pattern has completed another full cycle. All three payload files present in this snapshot are new arrivals; all three files from the prior snapshot have been retired.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence