Phoenix
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Phoenix is a threat actor known by the alias Phoenix and has been associated with the pro‑Russian hacker collective Killnet. Open‑source reporting indicates the group’s operators are based in Ukraine. The actor uses the name Phoenix in its communications, including Telegram posts where it claims responsibility for operations. Affiliation with Killnet has been cited in multiple threat intelligence reports linking the group to broader Russian‑aligned cyber activity. No other aliases have been publicly attributed to this actor in the available sources.
Phoenix has targeted both healthcare and financial/insurance sectors, as evidenced by intrusions against Indian health institutions and a major US insurance carrier. In the healthcare incidents the group claimed access to hospital management systems, patient and staff data, and asserted disruption of services. In the financial incident the actor deployed a ransomware variant referred to as Phoenix CryptoLocker, which appended the .phoenix extension to encrypted files. The ransomware attack leveraged remote access via VPN connections to encrypt over fifteen thousand devices across the victim’s network. The group’s public statements have linked its actions to geopolitical tensions, specifically citing sanctions against Russia as a motivating factor for the healthcare breach.
A representative operation occurred in March 2023 when Phoenix asserted it had compromised the Indian Health Ministry’s Health Management Information System and possessed sensitive data on hospitals, staff and patients. The intrusion was identified by CloudSEK’s XVigil platform and followed earlier disruptions to Indian healthcare infrastructure such as the AIIMS system outage. Another notable campaign took place in March 2021 when CNA Financial suffered a ransomware infection using the Phoenix CryptoLocker variant, affecting more than fifteen thousand endpoints. During that event the attackers left ransom notes and used the .phoenix file extension, though a definitive link to the Evil Corp criminal syndicate was not established by the victim. These two incidents illustrate the actor’s capability to conduct both data‑theft‑oriented breaches and financially motivated ransomware operations.
Incidents
Attributed incidents are available to members.
2 incidents