
Phorpiex Botnet Runs Six-Path C2 Panel With Tor Fallback to Target Mexico
A Phorpiex campaign active since June 2026 operates six sequentially numbered HTTP endpoints on a single Seychelles-geolocated IP, backed by a Tor hidden-service fallback. Its sole enriched payload scores clean in sandbox analysis despite 62 of 77 static engines flagging it — a time-based evasion gap that defines the campaign's operational advantage.
A single IP address geolocated to the Seychelles is currently serving six sequentially numbered HTTPendpoints — /cc11, /cc22, /cc33, /cc44, /cc55, and /cc66 — alongside a Tor hidden-service fallback, forming the operational backbone of an active Phorpiex botnet campaign targeting Mexico. CTX Team first observed this infrastructure on 4 June 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read