C&CMembers
C&C

Five-Year-Old Phorpiex Banker Still Fools Two of Six Sandboxes

A 2021-vintage Phorpiex/ClipBanker binary keeps checking into the same six-path, single-IP panel it always has, dodging Yomi Hunter and C2AE with basic timing and debugger checks while 64 of 76 engines flag it outright. The only real change this cycle is thin, largely unverifiable hash churn layered on top of unchanged infrastructure.

Sep 6, 2026, 06:41 (UTC+9)Last seenSep 6, 2026Severity100ByCTX TeamIOC12MITRE34RegionsBOKZMX

A Win32 executable built in May 2021 is still checking in against the same command-and-control panel it has used for years, and it is still winning against two of the six sandboxes that tried to detonate it. The file — 100KB, unsigned, carrying the threat label trojan.phorpiex/clipbanker (552ac091…9e17) — has been resubmitted 46 times from 37 unique sources, with a submission as recent as 2026-08-22 sitting on top of a compile timestamp from 2021-05-07.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence